Bug 2538414 (CVE-2026-63451) - CVE-2026-63451 suricata: Suricata: Denial of Service via crafted detection rule
Summary: CVE-2026-63451 suricata: Suricata: Denial of Service via crafted detection rule
Keywords:
Status: NEW
Alias: CVE-2026-63451
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2539202
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 18:30 UTC by OSIDB Bzimport
Modified: 2026-09-23 08:36 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 18:30:16 UTC
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, a locally supplied detection rule that combines frame inspection without content and a transformed match without content can make src/detect-engine-prefilter.c select multiple non-prefilter frame engines while preparing signatures for non-prefilter inspection. Loading the crafted rule, including in test mode, can trigger a heap buffer overflow and crash Suricata; network traffic alone cannot reach the flaw. This issue is fixed in version 8.0.6.


Note You need to log in before you can comment on or make changes to this bug.