CVE-2024-23839: Suricata http: heap use after free with http.request_header and http.response_header keywords
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.requestheader or http.responseheader keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.requestheader and http.responseheader keywords.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Suricatato a version that resolves this vulnerability.Fixed in 7.0.3 - Configuration
Update Suricata rulesets to avoid using the http.request_header and http.response_header keywords, since specially crafted traffic can trigger a heap use after free when these keywords are used in the ruleset prior to 7.0.3.
Suricata ruleset (HTTP keywords) use of http.request_header and http.response_header keywords = avoid
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23839?
CVE-2024-23839 is classified as high severity due to the potential for heap use after free vulnerabilities in Suricata.
How do I fix CVE-2024-23839?
To fix CVE-2024-23839, upgrade to Suricata version 7.0.3 or later.
What versions of Suricata are affected by CVE-2024-23839?
CVE-2024-23839 affects all versions of Suricata prior to 7.0.3.
What is the impact of CVE-2024-23839?
The impact of CVE-2024-23839 can lead to denial of service or arbitrary code execution due to heap memory corruption.
Which software distributions include affected versions for CVE-2024-23839?
Affected versions of CVE-2024-23839 are found in Fedora 38 and 39, as well as all Suricata versions prior to 7.0.3.