The vulnerability exists due to absent rate-limiting infrastructure during the handling of invalid or broken IPsec/ISAKMP security associations. A continuous flood of unauthenticated, garbage key exchange payloads forces Suricata to spend all its processing power generating error alerts, completely blinding the IDS engine.