Suricata 是一款网络入侵检测系统(IDS)、入侵防御系统(IPS)以及网络安全监控引擎。从版本 8.0.0 开始至 8.0.5 之前的版本中,当启用 Lua 规则执行时,Lua 沙箱的内存限制对新内存分配未得到一致地强制执行。某些 Lua 内存分配模式可能会超出 的设定值,却未触发预期的内存限制,导致所配置沙箱限制不可靠。该问题需要启用 Lua 规则并加载了受影响的 Lua 脚本/规则。版本 8.0.5 已包含修复。作为临时解决方案,除非确需使用 Lua 规则,否则应禁用 。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45747 | 7.5 HIGH | Suricata lua/tls: null dereference in TlsGetCertInfo |
| CVE-2026-46387 | 7.5 HIGH | Suricata http2: decompression bomb can cause denial of service in Suricata |
No comments yet