Database/Control plane, storage & DevOps
Suricata: unbounded NFS parser state lets crafted traffic exhaust sensor memory
Impact
NFS parser state structures are insufficiently bounded, so crafted NFS traffic makes the Suricata process consume memory until it is killed or the host starves. Where Suricata is the IDS watching the storage and management networks of a GPU fleet - and NFS is exactly what those networks carry for datasets and home directories - losing the sensor means losing visibility during the same traffic that triggered it. If the sensor is inline as an IPS, the failure is a traffic outage rather than just a blind spot. No confidentiality or integrity impact; this is availability only.
Who can reach it
Anyone who can get NFS traffic onto a segment Suricata inspects. No authentication to Suricata is involved - the sensor is a passive or inline observer of the wire.
What to do
Upgrade to Suricata 7.0.16 or 8.0.5 and restart the sensor; on an inline deployment plan for the brief gap or fail-open window that restart implies. Documented workaround if you cannot upgrade immediately: disable NFS application-layer parsing in suricata.yaml when you do not need it, which also requires a restart.
References
Related entries
- rclone (local backend, --links): When rclone copies from an untrusted remote with --links, it recreates symlinksCVE-2026-54572 · rclone (local backend, --links)High
- Jenkins Script Security Plugin: Groovy sandbox escape via AST annotation extensions memberCVE-2026-57281 · Jenkins Script Security Plugin (Groovy sandbox, AST transformation annotations)High
- GitLab CE/EE: improper input validation lets an unauthenticated user cause a denial of serviceCVE-2026-7427 · GitLab CE/EE (unauthenticated request path, improper input validation)High
- Splunk Enterprise Edge Processor sidecar: Prometheus metrics endpoint served without authenticationCVE-2026-76262 · Splunk Enterprise Edge Processor SPL2 Preview sidecar (Prometheus metrics endpoint)High
- ntpd (transmit timestamp prediction): A remote attacker who can predict transmit timestamps can crash ntpd or, worseCVE-2020-13817 · ntpd (transmit timestamp prediction)High
- Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN): A device plugged into a normal front-panel port can talk itsCVE-2021-1228 · Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.