PT-2026-95657 · Suricata · Suricata

CVE-2026-63451

·

Published

2026-07-21

·

Updated

2026-09-19

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Suricata versions 8.0.0 through 8.0.5
Description A heap buffer overflow can occur when loading a locally supplied detection rule that combines frame inspection without content and a transformed match without content. This causes the src/detect-engine-prefilter.c file to select multiple non-prefilter frame engines during signature preparation for non-prefilter inspection, leading to a system crash. This issue is triggered by loading a crafted rule, including in test mode, and cannot be exploited via network traffic alone.
Recommendations Update to version 8.0.6.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63451
GHSA-6QWQ-J83R-QP34

Affected Products

Suricata