Bug 2538145 (CVE-2026-63450)
| Summary: | CVE-2026-63450 Suricata: Suricata: Security bypass via FTP command sequence mishandling | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Suricata, a network Intrusion Detection System (IDS) and Intrusion Prevention System (IPS). A remote attacker can exploit a vulnerability in the FTP parser where sending a `RETR` or `STOR` command before `PORT` or `PASV` negotiation is incorrectly treated as a fatal error. This error disables further FTP application-layer parsing for the duration of the TCP connection, allowing subsequent commands to bypass detection rules and logging in IDS mode, or causing the flow to be dropped in IPS mode. This can lead to a security bypass, enabling attackers to evade security monitoring.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2539198, 2539200 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-22 17:17:41 UTC
|