Memory Vulnerability in Suricata's Network Security Monitoring Engine
CVE-2026-45751

5.9MEDIUM

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-45751?

Suricata’s network Intrusion Detection System is impacted by a memory corruption vulnerability wherein the inspection-buffer helper may retain a pointer to freed memory following a chained transform operation that triggers the reallocation of the backing buffer. This problem can emerge during specific network traffic processing activities and is contingent upon the use of particular rules, specifically those involving the chaining of the dotprefix transform. Users are advised to update to versions 7.0.16 or 8.0.5, which include remedial measures for this issue. Alternatively, users can mitigate the problem by avoiding the aforementioned rule configurations.

Affected Version(s)

suricata < 7.0.16 < 7.0.16

suricata >= 8.0.0, < 8.0.5 < 8.0.0, 8.0.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.