Executive brief
Suricata is a network security monitoring and intrusion detection system used to analyze traffic for threats. A vulnerability in its detection rule processing allows a malicious detection rule to cause the application to crash by triggering a use-after-free memory error, resulting in denial of service and loss of network visibility.
Technical details
A use-after-free vulnerability (CWE-416) exists in Suricata's decompress transform pipeline when certain detection transforms are chained together. Specifically, when gunzip or zlib_deflate transforms with max-size larger than 4096 are chained after another transform, the pipeline reads from an inspection buffer after it has been reallocated and freed. The vulnerability is triggered during network traffic processing and requires a malicious detection rule to exploit; it does not depend on specific malicious traffic content. An attacker with the ability to create or inject malicious Suricata detection rules can cause a denial of service by crashing the Suricata process. The issue is fixed in Suricata 8.0.5; a workaround exists by avoiding the vulnerable rule pattern.
Affected products
- OISF Suricata 8.0.0 to 8.0.4
Timeline
- 2026-06-02: disclosed
- 2026-05-19: patched: Fix released in Suricata 8.0.5