CVE-2026-22264
EUVD-2026-478227.01.2026, 19:16
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not run untrusted rulesets or run with less than 65536 signatures that can match on the same packet.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| oisf | suricata | 𝑥 < 7.0.14 |
| oisf | suricata | 8.0.0 ≤ 𝑥 < 8.0.3 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
References