Suricata 是一个网络入侵检测系统(NIDS)、入侵防御系统(NIPS)以及网络安全监控引擎。在版本 7.0.16 和 8.0.5 之前,恶意规则可能在加载或重新加载规则时覆盖文件系统中的任意文件。版本 7.0.16 和 8.0.5 已修复该问题。目前有一些临时解决方案可用:预处理 和 规则,禁止在 操作中使用绝对路径文件名;利用 Suricata 的权限降低机制限制可写文件范围;和/或在 suricata.yaml 中配置 landlock 以增强文件访问控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45764 | 9.1 CRITICAL | Suricata http2: protocol-change type confusion can lead to denial of service |
| CVE-2026-45747 | 7.5 HIGH | Suricata lua/tls: null dereference in TlsGetCertInfo |
| CVE-2026-46387 | 7.5 HIGH | Suricata http2: decompression bomb can cause denial of service in Suricata |
| CVE-2026-45759 | 7.5 HIGH | Suricata http1: quadratic Content-Disposition processing can lead to denial of service |
| CVE-2026-45762 | 7.5 HIGH | Suricata defrag: missing address-family check can lead to remote crash |
| CVE-2026-45769 | 7.5 HIGH | ikev2: unbounded client transform storage can lead to resource exhaustion |
| CVE-2026-45765 | 7.5 HIGH | Suricata dnp3: unbounded reassembly can lead to resource exhaustion |
| CVE-2026-45770 | 7.5 HIGH | Suricata lua: excessive flow variable registration can bypass sandbox |
| CVE-2026-45768 | 7.5 HIGH | Suricata ldap: unbounded responses per transaction can lead to resource exhaustion |
| CVE-2026-45766 | 7.5 HIGH | Suricata nfs: unbounded stateful structures can lead to resource exhaustion |
| CVE-2026-45763 | 5.9 MEDIUM | Suricata lua: sandbox allocation limit not enforced for new allocations |
| CVE-2026-45751 | 5.9 MEDIUM | Suricata detect/transform: use-after-free in dotprefix transform |
| CVE-2026-45752 | 5.9 MEDIUM | Suricata detect/transform: use-after-free in decompress transforms |
| CVE-2026-45761 | 3.3 LOW | Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rul |
No comments yet