Use-after-free in Suricata - #VU152930
Published: September 30, 2026
Vulnerability details
The vulnerability allows a local privileged user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to a use-after-free in lua/hashlib hash objects when matching traffic executes a malicious Lua rule script. A local privileged user can invoke __gc on an MD5, SHA-1, or SHA-256 object and then reuse it to execute arbitrary code or cause a denial of service.
Network traffic alone cannot trigger the issue without a malicious rule script.