Bug 2538813 (CVE-2026-63449)

Summary: CVE-2026-63449 Suricata: Suricata: Evasion of detection via large SIP message bodies
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Suricata, a network Intrusion Detection System (IDS) and Intrusion Prevention System (IPS). The Session Initiation Protocol (SIP) parser incorrectly handles large SIP message bodies. When a SIP message body exceeds 65,536 bytes, the parser truncates its length, preventing the full content from being inspected. This allows malicious content within the uninspected portion of the message to evade detection by the system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2539196    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-22 20:45:22 UTC
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fields. A SIP body larger than 65,536 bytes can truncate the length and prevent frame:request.body or frame:response.body from exposing the complete body to inspection, allowing content in the omitted portion to evade frame-based detection. This issue is fixed in version 8.0.6.