In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
{ "vanir_signatures": [ { "signature_version": "v1", "deprecated": false, "target": { "file": "src/detect-lua.c" }, "source": "https://github.com/oisf/suricata/commit/b95bbcc66db526ffcc880eb439dbe8abc87a81da", "digest": { "line_hashes": [ "103305860143753160792491287364709395789", "235129584418255779798626245926161842464", "293693393145250041927974542757688195874", "263275719835584498844336486386064445902", "297203217210655163813541935474860239733", "121731090351737341739739412241062912324", "182847789500480247703452451693903526470", "169203383410590033556495563816597827213" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2023-35853-4cb74c9c" }, { "signature_version": "v1", "deprecated": false, "target": { "file": "src/detect-lua.c", "function": "DetectLuaSetup" }, "source": "https://github.com/oisf/suricata/commit/b95bbcc66db526ffcc880eb439dbe8abc87a81da", "digest": { "length": 3090.0, "function_hash": "304649107609855633561903920416861928796" }, "signature_type": "Function", "id": "CVE-2023-35853-bc8b8fb4" }, { "signature_version": "v1", "deprecated": false, "target": { "file": "src/detect-lua.c", "function": "LuaMatchTest01" }, "source": "https://github.com/oisf/suricata/commit/b95bbcc66db526ffcc880eb439dbe8abc87a81da", "digest": { "length": 3945.0, "function_hash": "230516447770906724568909213276965772559" }, "signature_type": "Function", "id": "CVE-2023-35853-f14c3566" } ] }