Alpine: multiple suricata packages: security update to 8.0.6-r0

high Tenable Self-Hosted Container Security Plugin ID 446514

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering
can lead to a performance degradation. This issue has been patched in version 7.0.15. (CVE-2026-31937)

- Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the
"tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched
in version 8.0.4. (CVE-2026-31931)

- Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5
buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.
(CVE-2026-31932)

- Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted
traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in
versions 7.0.15 and 8.0.4. (CVE-2026-31933)

- Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a
quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a
performance impact. This issue has been patched in version 8.0.4. (CVE-2026-31934)

Solution

Update the suricata library and its related packages to version 8.0.6-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-31931

https://security.alpinelinux.org/vuln/CVE-2026-31932

https://security.alpinelinux.org/vuln/CVE-2026-31933

https://security.alpinelinux.org/vuln/CVE-2026-31934

https://security.alpinelinux.org/vuln/CVE-2026-31935

https://security.alpinelinux.org/vuln/CVE-2026-31937

Plugin Details

Severity: High

ID: 446514

Version: Revision 1.1

Type: Local

Published: 8/29/2026

Updated: 8/29/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.69

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-31937

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/2/2026

Reference Information

CVE: CVE-2026-31931, CVE-2026-31932, CVE-2026-31933, CVE-2026-31934, CVE-2026-31935, CVE-2026-31937

IAVB: 2026-B-0081-S