CVE-2024-38535: Suricata http2: oom from duplicate headers
Published Jul 11, 2024
·Updated
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.
Affected Software
2 affected components
OISF Suricata<6.0.20
OISF Suricata>=7.0.0<7.0.6
Remediation
Event History
Jul 11, 2024
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38535?
CVE-2024-38535 has a medium severity rating due to the potential for a denial of service condition.
2
How do I fix CVE-2024-38535?
To fix CVE-2024-38535, upgrade Suricata to version 6.0.20 or 7.0.6 or later.
3
What vulnerabilities does CVE-2024-38535 exploit?
CVE-2024-38535 exploits a vulnerability in the parsing of crafted HTTP/2 traffic.
4
Which versions of Suricata are affected by CVE-2024-38535?
CVE-2024-38535 affects Suricata versions prior to 6.0.20 and those between 7.0.0 and 7.0.6.
5
What impacts can CVE-2024-38535 have on my system?
The impact of CVE-2024-38535 can lead to Suricata running out of memory, potentially causing a denial of service.