5.5

CVE-2026-57225

Exploit

Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string. A trusted or untrusted dataset or rule feed containing a non-string value for that key can cause a NULL pointer dereference during startup, configuration test mode, or rule reload, crashing Suricata before traffic processing. This issue is fixed in version 8.0.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oisf ≫ Suricata Version >= 8.0.0 < 8.0.6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.018
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
Release Notes
https://github.com/OISF/suricata/security/advisories/GHSA-vqqx-88xw-qqvc
Vendor Advisory
Mitigation
https://github.com/OISF/suricata/pull/15699
Patch
https://github.com/OISF/suricata/commit/3ca2ed25a324597a85a2ab11595c3b0689468ea5
Patch
https://github.com/OISF/suricata/commit/bd3293aca714f5d090b73e7d9be0e5cd7e3f5f53
Patch
https://redmine.openinfosecfoundation.org/issues/8624
Third Party Advisory
Exploit
Issue Tracking
Mitigation