| Name | CVE-2026-63347 |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-6475-1 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| suricata-update (PTS) | bullseye | 1.2.1-1 | vulnerable |
| bookworm | 1.2.7-1 | vulnerable |
| trixie | 1.3.4-1 | vulnerable |
| trixie (security) | 1.3.4-1+deb13u1 | fixed |
| forky, sid | 1.3.8-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
https://github.com/OISF/suricata-update/security/advisories/GHSA-6v4p-4w5x-9fp2
https://redmine.openinfosecfoundation.org/issues/8633
Fixed by: https://github.com/OISF/suricata-update/commit/fae50697dff60364d6f0638908c6762eec3b421c (1.3.8)