CVE-2026-45767
Publication date 14 September 2026
Last updated 14 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule load or reload. Versions 7.0.16 and 8.0.5 fix the issue. Some workarounds are available. Preprocess `load`+ `save` rules to disallow absolute filenames for save, use Suricata's privilege dropping to limit writable files, and/or configure landlock in suricata.yaml.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| suricata | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
4.4 · Medium
Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-45767
- https://github.com/OISF/suricata/security/advisories/GHSA-gfxq-gffp-w9rv
- https://redmine.openinfosecfoundation.org/issues/8548 (suricata-7.0.16)
- https://redmine.openinfosecfoundation.org/issues/8547 (suricata-8.0.5)
- https://github.com/OISF/suricata/commit/477120e3409a2270e5d698c89e7dbd0a74f1f218 (suricata-7.0.16)
- https://github.com/OISF/suricata/commit/654f5fa64ffbb9ce855f178b7f45cce8ce72ce68 (suricata-8.0.5)
- https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
- https://redmine.openinfosecfoundation.org/issues/8546