CVE-2026-22264
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
27/01/2026
Last modified:
27/01/2026
Description
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not run untrusted rulesets or run with less than 65536 signatures that can match on the same packet.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/OISF/suricata/commit/549d7bf60616de8e54686a188196453b5b22f715
- https://github.com/OISF/suricata/commit/5789a3d3760dbf33d93fc56c27bd9529e5bdc8f2
- https://github.com/OISF/suricata/commit/ac1eb394181530430fb7262969f423a1bf8f209b
- https://github.com/OISF/suricata/security/advisories/GHSA-mqr8-m3m4-2hw5
- https://redmine.openinfosecfoundation.org/issues/8190



