CVE-2026-45747

NameCVE-2026-45747
DescriptionSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (`TlsGetCertInfo` function), or update scripts to handle missing certificate fields where possible.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
suricata (PTS)trixie1:7.0.10-1+deb13u4vulnerable
forky, sid1:8.0.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
suricatasource(unstable)1:8.0.1-1

Notes

https://github.com/OISF/suricata/security/advisories/GHSA-vfc5-9844-rmhv
https://redmine.openinfosecfoundation.org/issues/6286 (suricata-7.0.16)
https://github.com/OISF/suricata/commit/20fa5d773fd8ccebaa58294f59fb6cd50f55c4d5 (suricata-7.0.16)

Search for package or bug name: Reporting problems