Impact
A crafted Suricata rule that uses mixed‑case frame syntax can trigger a heap buffer overflow while the engine is loading signatures. The flaw is exercised during rule parsing, not by network traffic, and can lead to memory corruption that may allow arbitrary code execution or cause the Suricata process to terminate.
Affected Systems
Suricata versions prior to 7.0.16 and 8.0.5 are vulnerable. The security patch is included in 7.0.16 and 8.0.5 and later releases.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The rendered heap corruption is reached through rule parsing; based on the description, the likely attack vector is local or remote injection of malicious rule files or a compromise that allows installation of custom rulesets.
OpenCVE Enrichment