Impact
The vulnerability allows a Lua rule that registers an excessive number of flow variables to corrupt Suricata's internal detection state, which may enable an attacker to bypass the engine's restricted Lua sandbox and also cause Suricata to terminate unexpectedly. The flaw is tied to mismanagement of memory and input handling, reflected in the CWE identifiers for improper type handling and out‑of‑bounds writes. The issue exists in Suricata versions 8.0.0 through 8.0.4; it was fixed in version 8.0.5, so systems using the affected releases must upgrade.
Affected Systems
OISF Suricata deployments running version 8.0.0 through 8.0.4 are vulnerable. The security update that resolves the issue is included in version 8.0.5 and later.
Risk and Exploitability
The CVSS score of 7.5 indicates information is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to introduce a Lua rule that triggers the over‑registration of flow variables; thus the attack vector is considered likely local or via compromise of rule management processes.
OpenCVE Enrichment