CVE-2026-45767

    Dashboard / Vulnerabilities / CVE-2026-45767

    CVE-2026-45767

    Published: 10 Sept 2026Last Modified: 12 Sept 2026

    Summary: Suricata datasets: save to absolute filename can be bypassed when combined with load command

    Details: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule load or reload. Versions 7.0.16 and 8.0.5 fix the issue. Some workarounds are available. Preprocess `load`+ `save` rules to disallow absolute filenames for save, use Suricata's privilege dropping to limit writable files, and/or configure landlock in suricata.yaml.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 9956286fb89f9cad9e9f95b99dc751f8666617b7

    Affected versions

    suricata-8.0.4
    suricata-8.0.3
    suricata-8.0.2
    suricata-8.0.1
    suricata-8.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-45767 | CVE-DB