CVE-2026-22262

Source
https://cve.org/CVERecord?id=CVE-2026-22262
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22262.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-22262
Aliases
  • GHSA-9qg5-2gwh-xp86
Downstream
Related
Published
2026-01-27T18:18:52.922Z
Modified
2026-07-22T00:45:51.338903Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Suricata datasets: stack overflow when saving a set
Details

Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use rules with datasets save nor state options.

Database specific
{
    "cwe_ids": [
        "CWE-121"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22262.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/oisf/suricata

Affected ranges

Type
GIT
Repo
https://github.com/oisf/suricata
Events
Database specific
{
    "cpe": "cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.0.14"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.0.3"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

suricata-0.*
suricata-0.8.2
suricata-1.*
suricata-1.0.0
suricata-1.0.1
suricata-1.0.2
suricata-1.1
suricata-1.1beta1
suricata-1.1beta2
suricata-1.1beta3
suricata-1.1rc1
suricata-1.2
suricata-1.2.1
suricata-1.2beta1
suricata-1.2rc1
suricata-1.3
suricata-1.3.1
suricata-1.3beta1
suricata-1.3beta2
suricata-1.3rc1
suricata-1.4
suricata-1.4beta1
suricata-1.4beta2
suricata-1.4beta3
suricata-1.4rc1
suricata-2.*
suricata-2.0
suricata-2.0.1
suricata-2.0.1rc1
suricata-2.0.2
suricata-2.0beta1
suricata-2.0beta2
suricata-2.0rc1
suricata-2.0rc2
suricata-2.0rc3
suricata-2.1beta1
suricata-2.1beta2
suricata-2.1beta3
suricata-2.1beta4
suricata-3.*
suricata-3.0
suricata-3.0.1
suricata-3.0.1RC1
suricata-3.0RC1
suricata-3.0RC2
suricata-3.0RC3
suricata-3.1
suricata-3.1.1
suricata-3.1.2
suricata-3.1RC1
suricata-3.2
suricata-3.2.1
suricata-3.2RC1
suricata-3.2beta1
suricata-4.*
suricata-4.0.0
suricata-4.0.0-beta1
suricata-4.0.0-rc1
suricata-4.0.0-rc2
suricata-4.0.1
suricata-4.1.0
suricata-4.1.0-beta1
suricata-4.1.0-rc1
suricata-4.1.0-rc2
suricata-4.1.1
suricata-4.1.2
suricata-5.*
suricata-5.0.0
suricata-5.0.0-beta1
suricata-5.0.0-rc1
suricata-5.0.1
suricata-6.*
suricata-6.0.0
suricata-6.0.0-beta1
suricata-6.0.0-rc1
suricata-6.0.1
suricata-7.*
suricata-7.0.0
suricata-7.0.0-beta1
suricata-7.0.0-rc1
suricata-7.0.0-rc2
suricata-7.0.1
suricata-7.0.10
suricata-7.0.11
suricata-7.0.12
suricata-7.0.13
suricata-7.0.2
suricata-7.0.3
suricata-7.0.4
suricata-7.0.5
suricata-7.0.6
suricata-7.0.7
suricata-7.0.8
suricata-7.0.9
suricata-8.*
suricata-8.0.0
suricata-8.0.1
suricata-8.0.2

Database specific

vanir_signatures
[
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/0eff24213763c2aa2bb0957901d5dc1e18414dbf",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c",
            "function": "StringAsBase64"
        },
        "id": "CVE-2026-22262-0b40fece",
        "signature_type": "Function",
        "digest": {
            "length": 400.0,
            "function_hash": "154037490896831806358006482358817647467"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/d6bc718e303ecbec5999066b8bc88eeeca743658",
        "deprecated": false,
        "target": {
            "file": "src/util-thash.c",
            "function": "THashWalk"
        },
        "id": "CVE-2026-22262-1e82c43b",
        "signature_type": "Function",
        "digest": {
            "length": 598.0,
            "function_hash": "275776755724205905922563773624622501286"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/d6bc718e303ecbec5999066b8bc88eeeca743658",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c",
            "function": "StringAsBase64"
        },
        "id": "CVE-2026-22262-2650f2e5",
        "signature_type": "Function",
        "digest": {
            "length": 379.0,
            "function_hash": "331756201794466297449898683352394684632"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/27a2180bceaa3477419c78c54fce364398d011f1",
        "deprecated": false,
        "target": {
            "file": "src/util-thash.c",
            "function": "THashWalk"
        },
        "id": "CVE-2026-22262-2a2f8212",
        "signature_type": "Function",
        "digest": {
            "length": 606.0,
            "function_hash": "1272612047172010887792488064384342524"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/27a2180bceaa3477419c78c54fce364398d011f1",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c"
        },
        "id": "CVE-2026-22262-4fbc3524",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "180989228765868661052124973277587192831",
                "332110692014243431306566894447070210650",
                "60376262852376960047187173946034596243",
                "267545089897705870235042590771234185360"
            ]
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/0eff24213763c2aa2bb0957901d5dc1e18414dbf",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c"
        },
        "id": "CVE-2026-22262-647d122d",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "317595639519856596419803005740441849967",
                "332057221222937494923562981602780714264",
                "124735706788870365282529417617279640754",
                "66451570876459375425195139042087116583",
                "90031484803494372155140801774671844803",
                "95857530866892537229258036830918077943",
                "212752573881914920726297733985446846629"
            ]
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/27a2180bceaa3477419c78c54fce364398d011f1",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c",
            "function": "StringAsBase64"
        },
        "id": "CVE-2026-22262-73b7dff2",
        "signature_type": "Function",
        "digest": {
            "length": 369.0,
            "function_hash": "51080610540463873389444867353936666772"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/d6bc718e303ecbec5999066b8bc88eeeca743658",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c"
        },
        "id": "CVE-2026-22262-73eac21b",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "292427203768723999556687434906253751158",
                "218650949774491847320454160964943064914",
                "163075111524419533821015936781849042389",
                "256933124706638858817055268326161510300"
            ]
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/32609e6896f9079c175665a94005417cec7637eb",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c",
            "function": "StringAsBase64"
        },
        "id": "CVE-2026-22262-8d683d90",
        "signature_type": "Function",
        "digest": {
            "length": 390.0,
            "function_hash": "280957450008624890592522799831544889955"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/32a1b9ae6aa80a60c073897e38a2ac6ea0f64521",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c",
            "function": "StringAsBase64"
        },
        "id": "CVE-2026-22262-9ee118d0",
        "signature_type": "Function",
        "digest": {
            "length": 400.0,
            "function_hash": "154037490896831806358006482358817647467"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/d767dfadcd166f82683757818b9e46943326ac90",
        "deprecated": false,
        "target": {
            "file": "src/util-thash.c"
        },
        "id": "CVE-2026-22262-a791a1a5",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "113909285728151654201672568460754293604",
                "54617142051723409596810503810414856939",
                "77517838719717634714849399757734984968",
                "145115520504848877845670222826685971155"
            ]
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/32609e6896f9079c175665a94005417cec7637eb",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c"
        },
        "id": "CVE-2026-22262-c0e7c6e3",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "175090258311383592725833741735931773110",
                "97410289285780918518172444476503815655",
                "127902972864639942000914944165956103875",
                "191564500758309614797226614269063897232",
                "202711219848473278075119419227866056728",
                "243168745761788226280981211998103852846",
                "136373694045368324406840000646291621330",
                "261287275399647568927102753949510566219"
            ]
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/d767dfadcd166f82683757818b9e46943326ac90",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c"
        },
        "id": "CVE-2026-22262-c0f56396",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "292427203768723999556687434906253751158",
                "218650949774491847320454160964943064914",
                "163075111524419533821015936781849042389",
                "256933124706638858817055268326161510300"
            ]
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/d6bc718e303ecbec5999066b8bc88eeeca743658",
        "deprecated": false,
        "target": {
            "file": "src/util-thash.c"
        },
        "id": "CVE-2026-22262-cb9c35bb",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "113909285728151654201672568460754293604",
                "54617142051723409596810503810414856939",
                "77517838719717634714849399757734984968",
                "145115520504848877845670222826685971155"
            ]
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/d767dfadcd166f82683757818b9e46943326ac90",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c",
            "function": "StringAsBase64"
        },
        "id": "CVE-2026-22262-d4399e02",
        "signature_type": "Function",
        "digest": {
            "length": 379.0,
            "function_hash": "331756201794466297449898683352394684632"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/d767dfadcd166f82683757818b9e46943326ac90",
        "deprecated": false,
        "target": {
            "file": "src/util-thash.c",
            "function": "THashWalk"
        },
        "id": "CVE-2026-22262-dce1c504",
        "signature_type": "Function",
        "digest": {
            "length": 598.0,
            "function_hash": "275776755724205905922563773624622501286"
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/32a1b9ae6aa80a60c073897e38a2ac6ea0f64521",
        "deprecated": false,
        "target": {
            "file": "src/datasets-string.c"
        },
        "id": "CVE-2026-22262-f5779e24",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "317595639519856596419803005740441849967",
                "332057221222937494923562981602780714264",
                "124735706788870365282529417617279640754",
                "66451570876459375425195139042087116583",
                "90031484803494372155140801774671844803",
                "95857530866892537229258036830918077943",
                "212752573881914920726297733985446846629"
            ]
        }
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/oisf/suricata/commit/27a2180bceaa3477419c78c54fce364398d011f1",
        "deprecated": false,
        "target": {
            "file": "src/util-thash.c"
        },
        "id": "CVE-2026-22262-f6d0ac37",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "113909285728151654201672568460754293604",
                "54617142051723409596810503810414856939",
                "77517838719717634714849399757734984968",
                "145115520504848877845670222826685971155"
            ]
        }
    }
]
vanir_signatures_modified
"2026-07-22T00:45:51Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22262.json"