---
title: Closing a Suricata Supply Chain Attack Vulnerability
description: Stamus Security Platform (SSP) users are protected against the newly-announced Suricata supply chain vulnerability
image: https://www.stamus-networks.com/hubfs/Stamus-Closing-Suricata-Supply-Chain-Vuln.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# Closing a Suricata Supply Chain Attack Vulnerability

 by [Eric Leblond](https://www.stamus-networks.com/blog/author/eric-leblond) | Jun 15, 2023 | [SELKS](https://www.stamus-networks.com/blog/tag/selks), [Suricata](https://www.stamus-networks.com/blog/tag/suricata), [Stamus Security Platform](https://www.stamus-networks.com/blog/tag/stamus-security-platform), [CVE](https://www.stamus-networks.com/blog/tag/cve), [Stamus Labs](https://www.stamus-networks.com/blog/tag/stamus-labs)

![](https://www.stamus-networks.com/hubfs/Stamus-Closing-Suricata-Supply-Chain-Vuln.jpg)

On 15-June-2023 the OISF announced a new release of Suricata (6.0.13) which fixes a potential security issue that could lead to supply chain attacks against Suricata.  Specifically, this pertains to signatures which use [datasets](https://docs.suricata.io/en/suricata-6.0.13/rules/datasets.html?highlight=datasets#security) or Lua. Two CVEs were issued for these vulnerabilities. See links below:

CVE-2023-35852 - [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35852](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35852)   
CVE-2023-35853 - [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35853](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35853) 

Suricata 6.0.13 patches these vulnerabilities.

Here is the release notification: [https://forum.suricata.io/t/suricata-6-0-13-released/3595](https://forum.suricata.io/t/suricata-6-0-13-released/3595) 

The Stamus Networks team actually discovered the vulnerability and Stamus Security Platform (SSP) users were already protected against these newly-announced Suricata supply chain vulnerabilities with the U39 release issued in April 2023.

You can read about the U39 release here: [https://www.stamus-networks.com/blog/u39-for-stamus-security-platform-now-available](https://www.stamus-networks.com/blog/u39-for-stamus-security-platform-now-available?hsLang=en)

# Background: the evolution of Suricata signature sources

The intrusion detection (IDS) functionality of Suricata is dependent on signatures to power the detections. Historically, organizations have deployed a set of rules from a reputable source (such as ETPro and/or ETOpen) alongside some custom rules developed in house.  With the proliferation of multiple valuable sources of threat intelligence and rulesets, a modern Suricata deployment often involves rulesets from multiple sources sourced from the internet or from community platforms like MISP

This shift away from a trusted central provider \means the quality and security of these signatures can not be trusted by default. This is because Suricata is not simply a pattern matching engine.

# Powerful but potentially dangerous features in Suricata

One of the lesser-known features of Suricata is its support for the powerful Lua scripting language. Is it built by default by some distributions like Debian. This Lua support gives Suricata the capability of running a Lua script from within a signature. 

Lua is a powerful language and script execution is not sandboxed, so system interactions such as writing files or communicating over the network is possible. This means that a signature using Lua can run arbitrary code as the user running Suricata. This was a deliberate design choice, but the change in availability of untrusted signature sources requires that we revisit this decision and the implementation.

On top of that, Stamus Networks researchers uncovered another vulnerability relating to datasets. In releases prior to Suricata 6.0.13, the dataset feature could be abused by a signature to overwrite arbitrary files on the system. 

# Sources can not be trusted by default

Combining the fact that source of signatures can not be all trusted and the fact that some features of Suricata are potentially dangerous, we need to revisit the way the ruleset source management is performed. Giving unfettered access to all Suricata features is no longer safe.

At minimum, some features like Lua script execution and dataset save (before Suricata 6.0.13) must be disabled on sources we cannot trust.

# Built-in protection in Stamus Security Platform and SELKS

Beginning with update 39 (U39, announced in April 2023), Stamus Security Platform (SSP) and SELKS give users the ability to protect against these potential supply chain vulnerabilities. The protection takes place in Stamus Security Platform and SELKS using the "Source sanitization**"** configuration option on the ruleset “Source” page. 

NOTE: this option is enabled by default so you will need to disable it for your own signatures or for your most trusted sources.

See the screenshot below.

![](https://lh4.googleusercontent.com/N3pBi-o20JtC64IfZgzZZ5xdTlj4c7Pv67E8WDYlKrcxIApXit75wkDXWIX7q_y-d7WeSSvZ6qmszbPZ2rNJtorn2SgH081C5D97QYihm8gv_dh493LUhYVTqT19X_1M8D8e8rFLX8kKkL16ya8DYik)

# Fixed in Suricata 6.0.13

A fix for this issue was announced by the OISF on June 15, 2023. Suricata 6.0.13 will provide a flag to disable Lua rules when Lua is compiled in. With 6.0.13, absolute filenames and filenames attempting parent directory traversal using ".." will not be allowed by default. And finally, 6.0.13 adds 2 additional configuration parameters to Suricata:

- One parameter to *disable* this protection, reverting back to the old behavior which may be acceptable in controlled installations.
- One parameter to *disallow* rules that contain dataset *save* or *state* keywords, preventing any rules from having write access

Here is the release notification: [https://forum.suricata.io/t/suricata-6-0-13-released/3595](https://forum.suricata.io/t/suricata-6-0-13-released/3595)  

# Want to learn how to Supercharge your Suricata implementation?

# Check out this technical brief from Stamus Networks

 

[![Stamus_TB_Thumb_SuperSuri-1](https://www.stamus-networks.com/hs-fs/hubfs/Solution%20and%20Tech%20Briefs/Stamus_TB_Thumb_SuperSuri-1.jpg?width=600&height=337&name=Stamus_TB_Thumb_SuperSuri-1.jpg)](https://www.stamus-networks.com/hubfs/StamusNetworks_TB-SUPERSURI-032022-2.pdf?hsLang=en)

 

[ Download PDF ](https://www.stamus-networks.com/hubfs/StamusNetworks_TB-SUPERSURI-032022-2.pdf?hsLang=en)

 

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fclosing-a-suricata-supply-chain-attack-vulnerability%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fclosing-a-suricata-supply-chain-attack-vulnerability%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fclosing-a-suricata-supply-chain-attack-vulnerability%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fclosing-a-suricata-supply-chain-attack-vulnerability%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fclosing-a-suricata-supply-chain-attack-vulnerability%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fclosing-a-suricata-supply-chain-attack-vulnerability%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Eric Leblond](https://www.stamus-networks.com/hubfs/Stamus_Eric_Square-1.jpg)

#### Eric Leblond

 Éric Leblond is the co-founder and chief technology officer (CTO) at Stamus Networks. He sits on the board of directors at Open Network Security Foundation (OISF). Éric has more than 15 years of experience as co-founder and technologist of cybersecurity software companies and is an active member of the security and open-source communities. He has worked on the development of Suricata – the open-source network threat detection engine – since 2009 and is part of the Netfilter Core team, responsible for the Linux kernel's firewall layer. Eric is a respected expert and speaker on all things network security. Éric resides in Escalles, France.

[**](https://www.linkedin.com/in/ericleblond) [** ](https://twitter.com/Regiteric)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![](https://www.stamus-networks.com/hubfs/U42.2%20%281%29.png) ](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

### [Clear NDR® U42.2: A New Analyst Experience and a More Powerful AI Investigation Layer](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

At Stamus Networks, we measure releases by how much they improve the day-to-day work of security...

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/hubfs/SLS-1.3-18-Dec-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

### [Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

[Suricata Language Server](https://www.stamus-networks.com/suricata-language-server?hsLang=en) 1.3.0 is now available and it surfs on the concept of magic comment...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.