CVE-2026-22262 Details
Description
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use rules with datasets `save` nor `state` options.
A stack buffer overflow vulnerability has been identified in Suricata, a network IDS, IPS, and NSM engine, in versions prior to 7.0.14 and 8.0.3. The vulnerability arises when saving a dataset, as a stack buffer is used to prepare the data. If the dataset contains excessively large data, it can lead to a stack overflow. This issue can be exploited under certain conditions, particularly when rules with 'save' or 'state' options are used.
Users can upgrade to Suricata versions 7.0.14 or 8.0.3, where this vulnerability has been patched. If an upgrade is not possible, as a temporary measure, avoid using rules that incorporate datasets with 'save' or 'state' options.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| oisf suricata | < 7.0.14 >= 8.0.0, < 8.0.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 29, 2026 | Initial Analysis | [email protected] |
| Jan 27, 2026 | New CVE Received | [email protected] |