Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-45747— Suricata lua/tls: null dereference in TlsGetCertInfo

Quick assessment

Affected
OISF suricata
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Suricata 是一个网络入侵检测系统(IDS)、入侵防御系统(IPS)以及网络安全监控引擎。 在 7.0.16 版本之前,Lua TLS 证书信息辅助函数在处理某些证书字段缺失的 TLS 流量时,如果 Lua 脚本请求获取证书信息,可能会因解引用空的(NULL)证书字段而出现错误。经此漏洞,使用受影响 Lua TLS 脚本处理的特制 TLS 流量可能导致 Suricata 崩溃,从而导致服务中断(DoS)。 该问题已在 7.0.16 版本中修复。 临时规避措施:避免在对不可信流量调用 TLS 证书信息辅助函数(

CVSS 7.5 · High EPSS 0.05% · P15

Possible ATT&CK Techniques 2 AI

T1074 · Data Staged T1217.001
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45747

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Suricata lua/tls: null dereference in TlsGetCertInfo
Source: CVE Program / CVE List V5
Vulnerability Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (`TlsGetCertInfo` function), or update scripts to handle missing certificate fields where possible.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OISF suricata < 7.0.16 -

II. Public POCs for CVE-2026-45747

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45747

登录查看更多情报信息。

Vendor Advisories for CVE-2026-45747 (2)

Vendor Pages for CVE-2026-45747 (1)

Same Patch Batch · OISF · 2026-09-10 · 3 CVEs total

CVE-2026-46387 7.5 HIGH Suricata http2: decompression bomb can cause denial of service in Suricata
CVE-2026-45763 5.9 MEDIUM Suricata lua: sandbox allocation limit not enforced for new allocations

IV. Related Vulnerabilities

V. Comments for CVE-2026-45747

No comments yet


Leave a comment