<Vulnerability name="CVE-2026-45767">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-10T21:31:02</PublicDate>
    <Bugzilla id="2533941" url="https://bugzilla.redhat.com/show_bug.cgi?id=2533941" xml:lang="en:us">
suricata: Suricata: File overwrite via malicious rule load
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>4.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-73</CWE>
    <Details xml:lang="en:us" source="Mitre">
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule load or reload. Versions 7.0.16 and 8.0.5 fix the issue. Some workarounds are available. Preprocess `load`+ `save` rules to disallow absolute filenames for save, use Suricata's privilege dropping to limit writable files, and/or configure landlock in suricata.yaml.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Suricata, a network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring engine. A highly privileged remote attacker could exploit this vulnerability by crafting a malicious rule. When this rule is loaded or reloaded, it could allow the attacker to overwrite any file on the file system, leading to a loss of data integrity.
    </Details>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-45767
https://nvd.nist.gov/vuln/detail/CVE-2026-45767
https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
https://github.com/OISF/suricata/security/advisories/GHSA-gfxq-gffp-w9rv
https://redmine.openinfosecfoundation.org/issues/8546
    </References>
</Vulnerability>