CVE-2024-38535

Name
CVE-2024-38535
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/OISF/suricata/security/advisories/GHSA-cg8j-7mwm-v563
MISC https://github.com/OISF/suricata/commit/62d5cac1b8483d5f9d2b79833a4e59f5d80129b7
MISC https://github.com/OISF/suricata/commit/c82fa5ca0d1ce0bd8f936e0b860707a6571373b2
MISC https://redmine.openinfosecfoundation.org/issues/7104
MISC https://redmine.openinfosecfoundation.org/issues/7105
MISC https://redmine.openinfosecfoundation.org/issues/7112

Match rules

CPE URI Source package Min version Max version
suricata >= 0 < 6.0.20
suricata >= 7.0.0 < 7.0.6
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* suricata >= 0 < 6.0.20
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* suricata >= 7.0.0 < 7.0.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status