The vulnerability exists due to improper cleanup of temporary file descriptors used during network payload extraction. When Suricata dumps packet content to disk under heavy traffic conditions, unhandled exceptions can leak open file handlers until the process reaches OS limits and stops.