|
|
|
|
@ -1,3 +1,49 @@
|
|
|
|
|
8.0.6 -- 2026-07-07
|
|
|
|
|
|
|
|
|
|
Security #8653: mqtt: unbounded number of messages per tx (8.0.x backport)(HIGH - CVE 2026-57227)
|
|
|
|
|
Security #8650: smtp: evasion due to incomplete state reset (8.0.x backport)(MODERATE - CVE 2026-57229)
|
|
|
|
|
Security #8643: detect/file_data: heap buffer overflow in SWF decompression depth handling (8.0.x backport)(LOW - CVE 2026-57226)
|
|
|
|
|
Security #8627: windows: unquoted LocalSystem service ImagePath (8.0.x backport)(LOW - CVE 2026-57223)
|
|
|
|
|
Security #8625: datasets: NULL dereference on unexpected ndjson files (8.0.x backport)(LOW - CVE 2026-57225)
|
|
|
|
|
Security #8622: dhcp: unbounded tx growth with unidirectional traffic (8.0.x backport)(MODERATE - CVE 2026-57224)
|
|
|
|
|
Security #8568: ippair: IPv4/IPv6 hash collision can reuse wrong IPPair state (8.0.x backport)(MODERATE - CVE 2026-57222)
|
|
|
|
|
Security #8636: smb: unbounded memory for transactions on unidirectional flows (8.0.x backport)
|
|
|
|
|
Security #8591: detect: overflow on frame keyword use with pcre and transform (8.0.x backport)
|
|
|
|
|
Security #8637: applayer: transaction leak and O(n^2) CPU on passed flows (8.0.x backport)
|
|
|
|
|
Security #8726: doh2: quadratic complexity due to buffer not being reset (8.0.x backport)
|
|
|
|
|
Security #8657: sip: u16 truncation of body_len evades body inspection (8.0.x backport)
|
|
|
|
|
Security #8607: ftp: quadratic complexity in tx creation (8.0.x backport)
|
|
|
|
|
Security #8695: http1: multiple brotli bombs on a flow are slow (8.0.x backport)
|
|
|
|
|
Security #8660: ftp: RETR without PORT/PASV triggers permanent app-layer detection bypass (8.0.x backport)
|
|
|
|
|
Security #8570: flow: IPv4/IPv6 hash collision can reuse wrong flow state (8.0.x backport)
|
|
|
|
|
Bug #8723: rdp: transaction id handling can cause skips in tx cleanup (8.0.x backport)
|
|
|
|
|
Bug #8722: firewall: non-sequential tx causes issues (8.0.x backport)
|
|
|
|
|
Bug #8711: flow-manager: no flow timeout with flow.hash-size < 10 (8.0.x backport)
|
|
|
|
|
Bug #8696: ftp: support data channel for list, nlst, mlsd, appe, stou (8.0.x backport)
|
|
|
|
|
Bug #8670: ftp: can't proceed past banner in firewall mode (8.0.x backport)
|
|
|
|
|
Bug #8669: ftp: ftpdata_command never matches in firewall mode for active ftp (8.0.x backport)
|
|
|
|
|
Bug #8668: af-packet: IPS copy-mode startup race causes permanent ENOTSOCK on peer socket (8.0.x backport)
|
|
|
|
|
Bug #8655: pcap-file: failure reading pcaps from stdin or named pipe (8.0.x backport)
|
|
|
|
|
Bug #8652: conf: null deref when using YAML null values (8.0.x backport)
|
|
|
|
|
Bug #8646: firewall: accept-prior states logic doesn't work for built-in hooks (8.0.x backport)
|
|
|
|
|
Bug #8620: applayer: pass rules on UDP flows cause unbounded memory growth (8.0.x backport)
|
|
|
|
|
Bug #8616: decoder/ieee8021ah: missing layer check (8.0.x backport)
|
|
|
|
|
Bug #8614: defrag: memuse accounting error in alloc failure case (8.0.x backport)
|
|
|
|
|
Bug #8573: firewall: accept:flow at app-layer hook bypasses app:td (IDS/IPS) evaluation (8.0.x backport)
|
|
|
|
|
Bug #8498: firewall: limit packet scope to UDP app-layer (8.0.x backport)
|
|
|
|
|
Bug #8496: firewall: ruleset can skip hook if only later rules are present (8.0.x backport)
|
|
|
|
|
Feature #8611: firewall: Auto-Accept Prior States syntax for firewall mode intent rules (8.0.x backport)
|
|
|
|
|
Feature #8610: firewall: separate stats for ips and firewall (8.0.x backport)
|
|
|
|
|
Feature #8609: firewall: support generating alerts on default policy (8.0.x backport)
|
|
|
|
|
Feature #8602: firewall: drop action should not imply alert (8.0.x backport)
|
|
|
|
|
Feature #8574: firewall: configurable default policies (8.0.x backport)
|
|
|
|
|
Feature #8572: firewall: allow specifying multiple actions (8.0.x backport)
|
|
|
|
|
Feature #8564: firewall: support FTP hook states for firewall rule evaluation (8.0.x backport)
|
|
|
|
|
Feature #8519: firewall: analyzer: complete rule table coverage (8.0.x backport)
|
|
|
|
|
Task #8638: flowbits: deprecate "toggle" command
|
|
|
|
|
Task #8535: psl: crate should be updated on every release (8.0.x backport)
|
|
|
|
|
Documentation #8567: doc: improve manpage of suricatasc (8.0.x backport)
|
|
|
|
|
|
|
|
|
|
8.0.5 -- 2026-05-19
|
|
|
|
|
|
|
|
|
|
Security #8561: defrag: fragmented encapsulated traffic with fragments can lead to deadlock (8.0.x backport)(HIGH - CVE 2026-46352)
|
|
|
|
|
|