CVE-2026-22262: Suricata datasets: stack overflow when saving a set
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use rules with datasets save nor state options.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22262?
CVE-2026-22262 has a high severity due to the stack overflow risk it introduces in Suricata.
How do I fix CVE-2026-22262?
To fix CVE-2026-22262, upgrade Suricata to version 8.0.3 or 7.0.14 or later to mitigate the stack overflow vulnerability.
Which versions of Suricata are affected by CVE-2026-22262?
Suricata versions prior to 8.0.3 and 7.0.14 are affected by CVE-2026-22262.
What types of attacks can CVE-2026-22262 enable?
CVE-2026-22262 can potentially allow an attacker to cause a denial-of-service condition through stack overflow.
Is there a permanent solution for CVE-2026-22262?
The permanent solution for CVE-2026-22262 is to upgrade to the fixed versions of Suricata, specifically 8.0.3 or 7.0.14.