Impact
The suricata package on openSUSE Tumbleweed contains a Unix symbolic link following flaw that is triggered during its post‑install script. The flaw permits an unprivileged suricata user to create or influence a malicious symlink pointing to a privileged file, thereby allowing the suricata process to inadvertently overwrite root‑owned files. The result is local privilege escalation to root, corresponding to CWE‑59 (Relative Path Traversal) and CWE‑61 (Improper Control of File or Directory Access Path).
Affected Systems
All openSUSE Tumbleweed releases with Suricata before version 8.0.5-2.1 are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, whereas the EPSS score of below 1% suggests a very low probability of exploitation today. This vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access that can influence the post‑install script or the creation of a crafted symbolic link, so the attack vector is local. Successful exploitation would give the attacker root privileges, affecting confidentiality, integrity, and availability of the host.
OpenCVE Enrichment