Network Intrusion Detection System Vulnerability in Suricata by Open Information Security Foundation
CVE-2026-45763
5.9MEDIUM
What is CVE-2026-45763?
A vulnerability has been identified in Suricata, a network security platform, where the memory limit for Lua rule execution is not consistently enforced for new allocations. Specifically, Lua allocation patterns may exceed the configured memory limit (security.lua.max-bytes), creating a potential for memory overflow. This issue arises when Lua rules are enabled and could compromise the reliability of the sandbox environment. To mitigate risks, users are advised to disable Lua rules unless absolutely necessary, or upgrade to version 8.0.5, which addresses this vulnerability.
Affected Version(s)
suricata >= 8.0.0, < 8.0.5
