CVE-2026-22264: Suricata detect/alert: heap-use-after-free on alert queue expansion
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not run untrusted rulesets or run with less than 65536 signatures that can match on the same packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22264?
CVE-2026-22264 is classified as a critical vulnerability due to the potential for a heap-use-after-free condition impacting the stability and security of the Suricata software.
How do I fix CVE-2026-22264?
To fix CVE-2026-22264, upgrade Suricata to version 8.0.3 or 7.0.14 or later to mitigate the vulnerability.
What are the affected versions for CVE-2026-22264?
CVE-2026-22264 affects versions of Suricata prior to 8.0.3 and 7.0.14.
What causes the vulnerability in CVE-2026-22264?
CVE-2026-22264 is caused by an unsigned integer overflow leading to a heap-use-after-free condition during excessive alert generation for a single packet.
Is there a workaround for CVE-2026-22264 if I cannot upgrade?
There are no documented workarounds for CVE-2026-22264, so upgrading to the latest version is recommended.