7.5

CVE-2026-45770

Suricata lua: excessive flow variable registration can bypass sandbox

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua detection state and may bypass Suricata's restricted Lua sandbox. This requires an affected Lua script/rule to be loaded. Excessive flow variables being registered may also cause Suricata to crash. Version 8.0.5 contains a fix. As a workaround, disable `security.lua.allow-rules` unless Lua rules are required.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oisf ≫ Suricata Version >= 8.0.0 < 8.0.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
Vendor Advisory
Release Notes
https://github.com/OISF/suricata/security/advisories/GHSA-653j-cc95-vj4c
Third Party Advisory
https://redmine.openinfosecfoundation.org/issues/8556
Permissions Required