GPU VulnDB

Database/Control plane, storage & DevOps

Suricata: unbounded NFS parser state lets crafted traffic exhaust sensor memory

CVSS 7.5CVE-2026-45766Control plane, storage & DevOpscurated

Impact

NFS parser state structures are insufficiently bounded, so crafted NFS traffic makes the Suricata process consume memory until it is killed or the host starves. Where Suricata is the IDS watching the storage and management networks of a GPU fleet - and NFS is exactly what those networks carry for datasets and home directories - losing the sensor means losing visibility during the same traffic that triggered it. If the sensor is inline as an IPS, the failure is a traffic outage rather than just a blind spot. No confidentiality or integrity impact; this is availability only.

Who can reach it

Anyone who can get NFS traffic onto a segment Suricata inspects. No authentication to Suricata is involved - the sensor is a passive or inline observer of the wire.

What to do

Upgrade to Suricata 7.0.16 or 8.0.5 and restart the sensor; on an inline deployment plan for the brief gap or fail-open window that restart implies. Documented workaround if you cannot upgrade immediately: disable NFS application-layer parsing in suricata.yaml when you do not need it, which also requires a restart.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.