Executive brief
A security vulnerability in the Suricata network monitoring package on openSUSE Tumbleweed allows a local user with limited privileges to gain full administrative (root) control of the system. Suricata is a tool used for detecting and preventing network intrusions. By exploiting how the software handles file links, an attacker who already has access to the 'suricata' user account can take over the entire operating system, potentially leading to data theft or complete system compromise.
Technical details
A symbolic link (symlink) following vulnerability (CWE-61) exists in the Suricata package for openSUSE Tumbleweed. The flaw allows an attacker with access to the low-privileged 'suricata' user account to manipulate file operations via symlinks to gain root-level access. This is a local privilege escalation vulnerability that does not require user interaction. The issue is resolved in version 8.0.5-2.1 of the affected packages.
Affected products
- SUSE openSUSE Tumbleweed suricata package before 8.0.5-2.1
- SUSE openSUSE Tumbleweed suricata-devel package before 8.0.5-2.1
Timeline
- 2026-07-14: advisory: Initial publication of the CVE record.
- 2026-07-14: disclosed