Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59674

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1.

A flaw was found in suricata. This vulnerability, related to improper handling of symbolic links, allows a local suricata user to escalate their privileges to root. By exploiting this, an attacker could gain full control over the affected system.

Отчет

This issue is specific to the Suricata packaging shipped by openSUSE Tumbleweed: an unsafe recursive chown in the package's %post scriptlet follows symbolic links, allowing the local suricata user to escalate privileges to root during a package reinstall/upgrade. Red Hat's Suricata packages, built and maintained independently through Fedora and EPEL, do not contain this vulnerable packaging script and are not affected by this specific CVE.

Меры по смягчению последствий

No mitigation is necessary for Red Hat's Suricata packages, as they do not contain the vulnerable packaging script described in this CVE. Refer to the upstream openSUSE advisory for guidance on affected openSUSE Tumbleweed systems (fixed in suricata 8.0.5-2.1).

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2499909suricata: Suricata: Privilege escalation via symbolic link following

EPSS

Процентиль: 3%
0.00129
Низкий

8.8 High

CVSS3

Связанные уязвимости

nvd
21 день назад

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1.

debian
21 день назад

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tum ...

github
21 день назад

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1.

EPSS

Процентиль: 3%
0.00129
Низкий

8.8 High

CVSS3