Heap Buffer Overflow in Suricata Network Security Solutions
CVE-2026-45761
3.3LOW
What is CVE-2026-45761?
A severe vulnerability exists in Suricata, a leading network Intrusion Detection and Prevention System. When utilizing mixed-case frame syntax, a specially crafted rule can lead to a heap buffer overflow during the signature loading process. This issue occurs during the parsing and loading of rules, not solely from incoming network traffic. Users are urged to upgrade to versions 7.0.16 and 8.0.5 or later to ensure their systems are protected. As a precaution, it is recommended to preprocess rules to verify that frame syntax is in lowercase and to only use trusted rulesets.
Affected Version(s)
suricata >= 8.0.0, < 8.0.5 < 8.0.0, 8.0.5
suricata < 7.0.16 < 7.0.16
