CVE Explorer
CVE-2026-22264
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not run untrusted rulesets or run with less than 65536 signatures that can match on the same packet.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"suricata","vendor":"OISF","versions":[{"status":"affected","version":"< 7.0.14"},{"status":"affected","version":">= 8.0.0, < 8.0.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3921cb7c3b24e8f6ce2bee9c0097377e64c2dc9106f2a30e0da98dc06a33faf6 · sha256:e9e7071309603b7d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.4,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3921cb7c3b24e8f6ce2bee9c0097377e64c2dc9106f2a30e0da98dc06a33faf6 · sha256:e9e7071309603b7d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3921cb7c3b24e8f6ce2bee9c0097377e64c2dc9106f2a30e0da98dc06a33faf6 · sha256:e9e7071309603b7d… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/OISF/suricata/commit/549d7bf60616de8e54686a188196453b5b22f715","tags":["x_refsource_MISC"],"url":"https://github.com/OISF/suricata/commit/549d7bf60616de8e54686a188196453b5b22f715"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3921cb7c3b24e8f6ce2bee9c0097377e64c2dc9106f2a30e0da98dc06a33faf6 · sha256:e9e7071309603b7d… · /containers/cna/references/1
{"name":"https://github.com/OISF/suricata/commit/5789a3d3760dbf33d93fc56c27bd9529e5bdc8f2","tags":["x_refsource_MISC"],"url":"https://github.com/OISF/suricata/commit/5789a3d3760dbf33d93fc56c27bd9529e5bdc8f2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3921cb7c3b24e8f6ce2bee9c0097377e64c2dc9106f2a30e0da98dc06a33faf6 · sha256:e9e7071309603b7d… · /containers/cna/references/2
{"name":"https://github.com/OISF/suricata/commit/ac1eb394181530430fb7262969f423a1bf8f209b","tags":["x_refsource_MISC"],"url":"https://github.com/OISF/suricata/commit/ac1eb394181530430fb7262969f423a1bf8f209b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3921cb7c3b24e8f6ce2bee9c0097377e64c2dc9106f2a30e0da98dc06a33faf6 · sha256:e9e7071309603b7d… · /containers/cna/references/3
{"name":"https://github.com/OISF/suricata/security/advisories/GHSA-mqr8-m3m4-2hw5","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OISF/suricata/security/advisories/GHSA-mqr8-m3m4-2hw5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3921cb7c3b24e8f6ce2bee9c0097377e64c2dc9106f2a30e0da98dc06a33faf6 · sha256:e9e7071309603b7d… · /containers/cna/references/0
{"name":"https://redmine.openinfosecfoundation.org/issues/8190","tags":["x_refsource_MISC"],"url":"https://redmine.openinfosecfoundation.org/issues/8190"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3921cb7c3b24e8f6ce2bee9c0097377e64c2dc9106f2a30e0da98dc06a33faf6 · sha256:e9e7071309603b7d… · /containers/cna/references/4
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.