3.3

CVE-2026-45761

Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule load

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow while Suricata is loading signatures. The issue is reached during rule parsing/loading rather than by network traffic alone. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, preprocess rules to check that frames are all lowercase and/or only load trusted rulesets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oisf ≫ Suricata Version >= 7.0.0 < 7.0.16
Oisf ≫ Suricata Version >= 8.0.0 < 8.0.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
Vendor Advisory
Release Notes
https://github.com/OISF/suricata/security/advisories/GHSA-r74x-74x5-r9vm
Vendor Advisory
https://redmine.openinfosecfoundation.org/issues/8526
Permissions Required