Bug 2531457 (CVE-2026-45763) - CVE-2026-45763 suricata: Suricata: Denial of Service via un-enforced Lua sandbox memory limits
Summary: CVE-2026-45763 suricata: Suricata: Denial of Service via un-enforced Lua sand...
Keywords:
Status: NEW
Alias: CVE-2026-45763
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2531926 2531927
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-10 13:31 UTC by OSIDB Bzimport
Modified: 2026-09-11 15:04 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-10 13:31:28 UTC
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5,when Lua rule execution is enabled, the Lua sandbox memory limit was not consistently enforced for new allocations. Certain Lua allocation patterns could exceed `security.lua.max-bytes` without triggering the intended memory limit, making the configured sandbox limit unreliable. This requires Lua rules to be enabled and an affected Lua script/rule to be loaded. Version 8.0.5 contains a fix. As a workaround, disable `security.lua.allow-rules` unless Lua rules are required.


Note You need to log in before you can comment on or make changes to this bug.