CVE-2026-22262: Oisf Suricata

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use rules with datasets `save` nor `state` options.

Affected products

  • Oisf Suricata: before 7.0.14 (fixed in 7.0.14); from 8.0.0, before 8.0.3 (fixed in 8.0.3)

Published 2026-01-27. Last modified 2026-06-17.