VYPR

rpm package

opensuse/suricata&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/suricata&distro=openSUSE%20Tumbleweed

Vulnerabilities (75)

  • CVE-2026-57229MedSep 18, 2026
    affected < 8.0.6-1.1fixed 8.0.6-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An ou

  • CVE-2026-57228HigSep 18, 2026
    affected < 8.0.6-1.1fixed 8.0.6-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer when a quoted-printable escape seq

  • CVE-2026-57227HigSep 18, 2026
    affected < 8.0.6-1.1fixed 8.0.6-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a

  • CVE-2026-57224MedSep 18, 2026
    affected < 8.0.6-1.1fixed 8.0.6-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions without recording their packet direction with AppLayerTxData::for_

  • CVE-2026-57222MedSep 18, 2026
    affected < 8.0.6-1.1fixed 8.0.6-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash because src/ippair.c did not compare the IP address family before re

  • CVE-2026-46352HigSep 16, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's IP defragmentation code could deadlock when processing fragmented traffic containing an encapsula

  • CVE-2026-45770HigSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua detection state and may bypass Suricata's

  • CVE-2026-45769HigSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeated crafted UDP traffic may cause Suricata t

  • CVE-2026-45768HigSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of responses. Because LDAP can be processed over UDP,

  • CVE-2026-45767MedSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule load or reload. Versions 7.0.16 and 8.0.5 fix

  • CVE-2026-45766HigSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive m

  • CVE-2026-45765HigSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, DNP3 reassembly could buffer data without sufficient parser-level bounds. Crafted DNP3 traffic may cause Suricata to consume e

  • CVE-2026-45764CriSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause Suricata

  • CVE-2026-45762HigSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's IP defragmentation tracker lookup did not verify that an existing tracker used the same IP address family as the pa

  • CVE-2026-45761LowSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow while Suricata is loading signatures. The is

  • CVE-2026-45759HigSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform expensive parsing of large HTTP `Content-Disposition` headers during HTTP response body proc

  • CVE-2026-45752MedSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when certain detection transforms are chained, the decompress transform pipeline could read from an inspecti

  • CVE-2026-45751MedSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's inspection-buffer helper could leave an inspection pointer referencing freed memory after a chained transform cause

  • CVE-2026-46387HigSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed response-body buffer without an effective upper bound. A craf

  • CVE-2026-45763MedSep 10, 2026
    affected < 8.0.5-1.1fixed 8.0.5-1.1

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when Lua rule execution is enabled, the Lua sandbox memory limit was not consistently enforced for new alloc

Page 1 of 4