suricata (1:7.0.10-1+deb13u3) trixie; urgency=medium
* Fix CVE-2026-22258 in 7.0.10.
Cherry-Picked from:
*
f82a388d0283725cb76782cf64e8341cab370830
*
df389f8a43a06c718bb336ea082d6c80d6fefda0
*
c9b80e5affe073ce9d95d0c935a8d67647c83bf7
* Fix CVE-2026-22262 in 7.0.10.
Cherry-Picked from:
*
32609e6896f9079c175665a94005417cec7637eb
*
27a2180bceaa3477419c78c54fce364398d011f1
* Fix CVE-2026-22264 in 7.0.10.
Cherry-Picked from
5789a3d3760dbf33d93fc56c27bd9529e5bdc8f2.
* Fix CVE-2026-22259 in 7.0.10.
Cherry-Picked from:
*
63225d5f8ef64cc65164c0bb1800730842d54942
*
635af8dc8be09667689be71d781912718ca1aa49
*
fdd79bdb14488244604729f1d68ca4bc60000dbd
*
a6d950315d9b6c1e35c10c24d9bb7128d422c21f
With this fix, DNP3 has reduced the default maximum number of
outstanding transactions from 500 down to 32.
Read the update instructions for Suricata 7.0.14 for more details.
* Fix CVE-2026-22261 in 7.0.10.
Cherry-Picked from:
*
44d0c81f537f230e9215c769453fb4d7214217a1
*
7e704a3f50690b5f5d5cc573147ef41449fe37ac
[dgit import unpatched suricata 1:7.0.10-1+deb13u3]