Suricata 是一款网络入侵检测系统(IDS)、入侵防御系统(IPS)及网络安全监控引擎。 在 8.0.0 版本及之后、但低于 8.0.5 的版本中,当某些检测变换(detection transforms)被链式组合使用时, (解压缩)变换管道可能在检查缓冲区(inspection buffer)被重新分配并释放后仍尝试从中读取数据,从而导致内存错误。该问题在网络流量处理过程中被触发,但需要存在恶意规则;若缺少此类规则,Suricata 无论收到何种流量都会崩溃。 8.0.5 版本已包含对该问题的修复。 临时
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45764 | 9.1 CRITICAL | Suricata http2: protocol-change type confusion can lead to denial of service |
| CVE-2026-45747 | 7.5 HIGH | Suricata lua/tls: null dereference in TlsGetCertInfo |
| CVE-2026-46387 | 7.5 HIGH | Suricata http2: decompression bomb can cause denial of service in Suricata |
| CVE-2026-45759 | 7.5 HIGH | Suricata http1: quadratic Content-Disposition processing can lead to denial of service |
| CVE-2026-45762 | 7.5 HIGH | Suricata defrag: missing address-family check can lead to remote crash |
| CVE-2026-45769 | 7.5 HIGH | ikev2: unbounded client transform storage can lead to resource exhaustion |
| CVE-2026-45765 | 7.5 HIGH | Suricata dnp3: unbounded reassembly can lead to resource exhaustion |
| CVE-2026-45770 | 7.5 HIGH | Suricata lua: excessive flow variable registration can bypass sandbox |
| CVE-2026-45768 | 7.5 HIGH | Suricata ldap: unbounded responses per transaction can lead to resource exhaustion |
| CVE-2026-45766 | 7.5 HIGH | Suricata nfs: unbounded stateful structures can lead to resource exhaustion |
| CVE-2026-45763 | 5.9 MEDIUM | Suricata lua: sandbox allocation limit not enforced for new allocations |
| CVE-2026-45751 | 5.9 MEDIUM | Suricata detect/transform: use-after-free in dotprefix transform |
| CVE-2026-45767 | 4.4 MEDIUM | Suricata datasets: save to absolute filename can be bypassed when combined with load comma |
| CVE-2026-45761 | 3.3 LOW | Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rul |
No comments yet