Suricata Out of Memory Parsing Crafted HTTP/2 Traffic
CVE-2024-38535
7.5HIGH
What is CVE-2024-38535?
Suricata, a versatile network Intrusion Detection and Prevention System, can experience severe memory management issues when parsing crafted HTTP/2 requests. Attackers can exploit this vulnerability to cause the system to run out of memory, potentially disrupting network security monitoring capabilities. Users are advised to upgrade to Suricata version 6.0.20 or 7.0.6 to mitigate the risks associated with this vulnerability.
Affected Version(s)
suricata < 6.0.20 < 6.0.20
suricata >= 7.0.0, < 7.0.6 < 7.0.0, 7.0.6
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved