CVE-2024-23836: crafted traffic can cause denial of service
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft traffic to cause Suricata to use far more CPU and memory for processing the traffic than needed, which can lead to extreme slow downs and denial of service. This vulnerability is patched in 6.0.16 or 7.0.3. Workarounds include disabling the affected protocol app-layer parser in the yaml and reducing the stream.reassembly.depth value helps reduce the severity of the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Suricatato a version that resolves this vulnerability.Fixed in 6.0.16 - Upgrade
Upgrade
Suricatato a version that resolves this vulnerability.Fixed in 7.0.3 - Configuration
In the Suricata YAML, disable the affected protocol app-layer parser to work around the issue.
Suricata (YAML app-layer parser) Disable affected protocol app-layer parser (YAML) = disabled - Configuration
Reduce the `stream.reassembly.depth` value in Suricata configuration to help reduce the severity of the issue.
Suricata stream.reassembly.depth = reduced
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23836?
CVE-2024-23836 is classified as a resource exhaustion vulnerability that may lead to degraded performance of the Suricata engine.
How do I fix CVE-2024-23836?
To fix CVE-2024-23836, upgrade to Suricata version 6.0.16 or 7.0.3 or later.
What software is affected by CVE-2024-23836?
CVE-2024-23836 affects Suricata versions prior to 6.0.16 and from 7.0.0 to 7.0.2, as well as specific Fedora releases.
What are the potential impacts of CVE-2024-23836?
The potential impacts of CVE-2024-23836 include excessive CPU and memory usage when processing crafted traffic.
Is CVE-2024-23836 an easily exploitable vulnerability?
Yes, CVE-2024-23836 can be exploited through specially crafted network traffic, making it easily exploitable.