<Vulnerability name="CVE-2026-59674">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-14T07:32:35</PublicDate>
    <Bugzilla id="2499909" url="https://bugzilla.redhat.com/show_bug.cgi?id=2499909" xml:lang="en:us">
suricata: Suricata: Privilege escalation via symbolic link following
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-59</CWE>
    <Details xml:lang="en:us" source="Mitre">
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root.






This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in suricata. This vulnerability, related to improper handling of symbolic links, allows a local `suricata` user to escalate their privileges to root. By exploiting this, an attacker could gain full control over the affected system.
    </Details>
    <Statement xml:lang="en:us">
This issue is specific to the Suricata packaging shipped by openSUSE Tumbleweed: an unsafe recursive chown in the package's %post scriptlet follows symbolic links, allowing the local suricata user to escalate privileges to root during a package reinstall/upgrade. Red Hat's Suricata packages, built and maintained independently through Fedora and EPEL, do not contain this vulnerable packaging script and are not affected by this specific CVE.
    </Statement>
    <Mitigation xml:lang="en:us">
No mitigation is necessary for Red Hat's Suricata packages, as they do not contain the vulnerable packaging script described in this CVE. Refer to the upstream openSUSE advisory for guidance on affected openSUSE Tumbleweed systems (fixed in suricata 8.0.5-2.1).
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-59674
https://nvd.nist.gov/vuln/detail/CVE-2026-59674
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59674
    </References>
</Vulnerability>