Impact
A stack overflow that causes Suricata to crash can occur if SWF decompression is enabled.
Patches
Update to Suricata 7.0.13 or 8.0.2.
Workarounds
Disable SWF decompression (swf-decompression in suricata.yaml) ; it is disabled by default.
If you must enable it, set decompress-depth to lower than half your stack size.
References
https://redmine.openinfosecfoundation.org/issues/8055
Impact
A stack overflow that causes Suricata to crash can occur if SWF decompression is enabled.
Patches
Update to Suricata 7.0.13 or 8.0.2.
Workarounds
Disable SWF decompression (
swf-decompressionin suricata.yaml) ; it is disabled by default.If you must enable it, set
decompress-depthto lower than half your stack size.References
https://redmine.openinfosecfoundation.org/issues/8055