CVE-2026-22264

7.4

OISF · Suricata

Suricata versions prior to 7.0.14 and 8.0.3 are vulnerable to a heap use-after-free condition caused by an unsigned integer overflow when generating excessive alerts for a single packet.

Executive summary

A heap use-after-free vulnerability in the Suricata network engine allows an unauthenticated remote attacker to potentially cause a denial of service or impact system integrity.

Vulnerability

The flaw is a heap use-after-free (CWE-416) triggered by an unsigned integer overflow during the alert generation process for high-traffic packets. This vulnerability is exploitable by an unauthenticated remote attacker capable of sending traffic that triggers excessive rule matches.

Business impact

The exploitation of this vulnerability could lead to significant service disruption, as Suricata is a critical component for network intrusion detection and prevention. Given the CVSS score of 7.4, the risk is classified as High, reflecting the potential for system instability or integrity compromise within security infrastructure that relies on this engine for traffic inspection.

Remediation

Immediate Action: Upgrade to Suricata version 7.0.14 or 8.0.3 immediately to apply the vendor-provided patch.

Proactive Monitoring: Monitor system logs for unexpected crashes or service restarts of the Suricata process, which may indicate exploitation attempts.

Compensating Controls: If patching is not immediately feasible, reduce the complexity of active rulesets or ensure the system does not process untrusted rulesets to minimize the likelihood of triggering the overflow.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a notable risk to network security infrastructure and should be addressed with high priority. Organizations utilizing Suricata for critical traffic filtering must schedule the update to 7.0.14 or 8.0.3 during the next available maintenance window to ensure continued system stability and protection against potential exploitation.

Sources