---
title: "CVE-2026-45752\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-45752?format=md
keywords: index, follow
---

# CVE-2026-45752

Publication date 14 September 2026

Last updated 14 September 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.9 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2026-45752?format=md#impact-score)

Toggle side navigation

## Description

Suricata is a network Intrusion Detection System, Intrusion Prevention
System and Network Security Monitoring engine. Starting in version 8.0.0
and prior to version 8.0.5, when certain detection transforms are chained,
the decompress transform pipeline could read from an inspection buffer
after it had been reallocated and freed. The issue is reached during
network traffic processing, but requires a malicious rule as Suricata will
crash whatever the traffic. Version 8.0.5 contains a fix. As a workaround,
avoid rules that chain `gunzip` or `zlib\_deflate` with `max-size` bigger
than 4096 after another transform.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| suricata | 26.04 LTS resolute | Needs evaluation |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.9 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.9 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45752)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-45752)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-45752)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-45752)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-45752>
* <https://github.com/OISF/suricata/security/advisories/GHSA-qmc9-vqq2-8mv3>
* <https://redmine.openinfosecfoundation.org/issues/8541 (suricata-8.0.5)>
* <https://github.com/OISF/suricata/commit/11d1fe1ca866d82e8bb3dd4493016188d890aebd (suricata-8.0.5)>
* <https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315>
* <https://redmine.openinfosecfoundation.org/issues/8536>
