CVE-2024-37151: Suricata defrag: IP ID reuse can lead to policy bypass
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable defrag to reduce the scope of the problem.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37151?
CVE-2024-37151 has a high severity rating due to its potential for policy bypass in network security.
How do I fix CVE-2024-37151?
To fix CVE-2024-37151, upgrade to Suricata version 7.0.6 or 6.0.20 or later.
What causes CVE-2024-37151?
CVE-2024-37151 is caused by the mishandling of multiple fragmented packets with the same IP ID value.
Which versions of Suricata are affected by CVE-2024-37151?
CVE-2024-37151 affects Suricata versions prior to 7.0.6 and those between 6.0.0 and 6.0.20.
What can happen if CVE-2024-37151 is exploited?
If exploited, CVE-2024-37151 can lead to packet reassembly failure, allowing policies to be bypassed.