CVE-2024-38536: Suricata http/range: NULL-ptr deref when http.memcap is reached
Published Jul 11, 2024
·Updated
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to http.memcap being reached leads to a NULL-ptr reference leading to a crash. Upgrade to 7.0.6.
Affected Software
1 affected component
OISF Suricata<7.0.6
Event History
Jul 11, 2024
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38536?
CVE-2024-38536 is a high-severity vulnerability that can lead to a crash of the Suricata service.
2
How do I fix CVE-2024-38536?
To fix CVE-2024-38536, upgrade Suricata to version 7.0.6 or later.
3
What is the cause of CVE-2024-38536?
CVE-2024-38536 is caused by a memory allocation failure when the http.memcap limit is reached.
4
Which versions of Suricata are affected by CVE-2024-38536?
Suricata versions prior to 7.0.6 are affected by CVE-2024-38536.
5
What type of vulnerability is CVE-2024-38536?
CVE-2024-38536 is a memory management vulnerability that results in a null pointer dereference leading to a crash.