File Overwrite Vulnerability in Suricata Network Security Engine
CVE-2026-45767
What is CVE-2026-45767?
Suricata, a prominent network Intrusion Detection and Prevention System, has been identified to possess a vulnerability that allows a malicious rule to potentially overwrite any file on the file system during rule loading or reloading. This poses a risk to file system integrity for users utilizing versions prior to 7.0.16 and 8.0.5. To mitigate this issue, administrators can employ certain workarounds: preprocess load and save rules to avoid using absolute filenames, utilize Suricata's privilege dropping feature to restrict writable files, and configure the Landlock security module in the suricata.yaml file. Upgrading to the latest versions will also resolve this vulnerability effectively.
Affected Version(s)
suricata >= 8.0.0, < 8.0.5 < 8.0.0, 8.0.5
suricata < 7.0.16 < 7.0.16
