Executive brief
Suricata is a network security monitoring and intrusion detection/prevention system used to analyze traffic for threats. A maliciously crafted detection rule with mixed-case frame syntax can trigger a heap buffer overflow when Suricata loads signatures, potentially causing the service to crash and disrupting threat monitoring capabilities. This requires an attacker to provide or modify the ruleset being loaded.
Technical details
A heap-based buffer overflow (CWE-122) occurs in Suricata's rule parsing logic when processing frame syntax with mixed case. The vulnerability is triggered during rule loading/parsing, not by network traffic, and requires the attacker to control or influence the ruleset being loaded by Suricata. The flaw allows limited impact to availability (service DoS) with low privilege and local attack requirements. Patches are available in versions 7.0.16 and 8.0.5; workarounds include preprocessing rules to enforce lowercase frame syntax and only loading trusted rulesets.
Affected products
- OISF Suricata before 7.0.16 and 8.0.5
Timeline
- 2026-06-02: disclosed
- 2026-05-19: patched