First published: Thu Jul 11 2024(Updated: )
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OISF Suricata | <6.0.20 | |
OISF Suricata | >=7.0.0<7.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38535 has a medium severity rating due to the potential for a denial of service condition.
To fix CVE-2024-38535, upgrade Suricata to version 6.0.20 or 7.0.6 or later.
CVE-2024-38535 exploits a vulnerability in the parsing of crafted HTTP/2 traffic.
CVE-2024-38535 affects Suricata versions prior to 6.0.20 and those between 7.0.0 and 7.0.6.
The impact of CVE-2024-38535 can lead to Suricata running out of memory, potentially causing a denial of service.