7.5

CVE-2026-45747

Exploit

Suricata lua/tls: null dereference in TlsGetCertInfo

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (`TlsGetCertInfo` function), or update scripts to handle missing certificate fields where possible.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oisf ≫ Suricata Version < 7.0.16
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://github.com/OISF/suricata/security/advisories/GHSA-vfc5-9844-rmhv
Vendor Advisory
Mitigation
https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
Vendor Advisory
Release Notes
https://redmine.openinfosecfoundation.org/issues/6286
Vendor Advisory
Exploit
Issue Tracking