Hello,
I have noticed during a huge file transfer over SMB that suricata started to use up to all memory (16 GB RAM) on my 19.1.10-amd64 machine. That can't be normal.
Suricata is on version 4.1.4_2.
Regards,
GOCE
I would recommend reporting this upstream because we can only speculate from here.
https://redmine.openinfosecfoundation.org/projects/suricata
Cheers,
Franco
OK, thanks.
I'll report it upstream. Was just curious if others experienced a similar behavior. I have suricata running for several years now and never observed something like this.
Regards,
GOCE
SMB received a couple of updates in 4.1 so maybe that's that. Newer decoders are written in Rust which are supposed to be leak-proof so I guess this thing is not because it's not written in Rust.
Cheers,
Franco