VYPR

rpm package

opensuse/suricata&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/suricata&distro=openSUSE%20Tumbleweed

Vulnerabilities (54)

  • CVE-2026-31937HigApr 2, 2026
    affected < 8.0.4-1.1fixed 8.0.4-1.1

    Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in version 7.0.15.

  • CVE-2026-31935HigApr 2, 2026
    affected < 8.0.4-1.1fixed 8.0.4-1.1

    Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions

  • CVE-2026-31934HigApr 2, 2026
    affected < 8.0.4-1.1fixed 8.0.4-1.1

    Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This issue has been patched in version 8.0.4.

  • CVE-2026-31933HigApr 2, 2026
    affected < 8.0.4-1.1fixed 8.0.4-1.1

    Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4.

  • CVE-2026-31932HigApr 2, 2026
    affected < 8.0.4-1.1fixed 8.0.4-1.1

    Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.

  • CVE-2026-31931HigApr 2, 2026
    affected < 8.0.4-1.1fixed 8.0.4-1.1

    Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.

  • CVE-2026-22264Jan 27, 2026
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround,

  • CVE-2026-22263Jan 27, 2026
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.

  • CVE-2026-22262Jan 27, 2026
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a work

  • CVE-2026-22261Jan 27, 2026
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in

  • CVE-2026-22260Jan 27, 2026
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As a workaround, use default values for `request-body-limit` and `response-body-limit`.

  • CVE-2026-22259Jan 27, 2026
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading

  • CVE-2026-22258Jan 27, 2026
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC

  • CVE-2025-64344Nov 26, 2025
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts

  • CVE-2025-64330Nov 26, 2025
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a single byte read heap overflow when logging the verdict in eve.alert and eve.drop records can lead to crash

  • CVE-2025-64331Nov 26, 2025
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow can occur on large HTTP file transfers if the user has increased the HTTP response body limi

  • CVE-2025-64332Nov 26, 2025
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow that causes Suricata to crash can occur if SWF decompression is enabled. This issue has been

  • CVE-2025-64333Nov 26, 2025
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a large HTTP content type, when logged can cause a stack overflow crashing Suricata. This issue has been patc

  • CVE-2025-64335Nov 26, 2025
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue

  • CVE-2025-64334Nov 26, 2025
    affected < 8.0.3-1.1fixed 8.0.3-1.1

    Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patche

Page 1 of 3