Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe decompress-depth can use the configured depth when allocating in src/util-file-decompression.c instead of limiting the allocation to the Flash file's actual data requirement. A crafted SWF response can therefore trigger an integer-related heap buffer overflow and crash Suricata; the default disabled feature and default depth are not affected. This issue is fixed in versions 8.0.6 and 7.0.17.
Published: 2026-09-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A crafted Adobe Flash file can trigger an integer-related heap buffer overflow in Suricata’s HTTP SWF decompression routine when the non‑default swf‑decompression feature is enabled and an unsafe decompress‑depth is used. The vulnerability allows a malicious response to cause Suricata to allocate an insufficient buffer on the heap, resulting in a crash. This flaw is a classic Heap Buffer Overflow (CWE‑122) combined with an Integer Overflow (CWE‑190) that leads to loss of service rather than arbitrary code execution.

Affected Systems

The issue affects the Suricata network intrusion detection and prevention engine developed by the Open Information Security Foundation. Versions earlier than 7.0.17 and 8.0.6 that have the swf‑decompression feature enabled and an unsafe depth setting are vulnerable. All other versions, including those with the feature disabled or the default depth, are not impacted.

Risk and Exploitability

Suricata receives a CVSS score of 3.7, indicating low severity. Exploit probability data (EPSS) is not available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker can remotely deliver a malicious SWF document to Suricata over HTTP; when the vulnerable de‑compression logic processes the file, the service will crash, disrupting network monitoring. The attack requires the feature to be enabled and a non‑default depth, which are not set by default, reducing the attack surface but still allowing exploitation from a remote source.

Generated by OpenCVE AI on September 19, 2026 at 10:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 7.0.17 or later, which includes the fix for the unsafe decompress‑depth logic.
  • Verify that the swf‑decompression feature remains disabled or that the configuration uses the default, safe depth value if the feature must remain enabled.
  • If an upgrade cannot be applied immediately, temporarily disable the swf‑decompression feature in the Suricata configuration file until the patched version is available.

Generated by OpenCVE AI on September 19, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe decompress-depth can use the configured depth when allocating in src/util-file-decompression.c instead of limiting the allocation to the Flash file's actual data requirement. A crafted SWF response can therefore trigger an integer-related heap buffer overflow and crash Suricata; the default disabled feature and default depth are not affected. This issue is fixed in versions 8.0.6 and 7.0.17.
Title Suricata swf: heap buffer overflow in SWF decompression depth handling
Weaknesses CWE-122
CWE-190
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T15:45:53.283Z

Reserved: 2026-06-24T02:21:33.811Z

Link: CVE-2026-57226

cve-icon Vulnrichment

Updated: 2026-09-22T15:45:46.986Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:17.947

Modified: 2026-09-28T18:36:20.180

Link: CVE-2026-57226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound