High severity7.5NVD Advisory· Published Oct 23, 2017· Updated May 13, 2026
CVE-2017-15377
CVE-2017-15377
Description
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engine-content-inspection.c. The search engine doesn't stop when it should after no match is found; instead, it stops only upon reaching inspection-recursion-limit (3000 by default).
Affected products
1- cpe:2.3:a:openinfosecfoundation:suricata:*:*:*:*:*:*:*:*Range: <=3.2.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.