First published: Thu Jul 11 2024(Updated: )
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads to a NULL-ptr reference leading to a crash. Upgrade to 7.0.6.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OISF Suricata | <7.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38536 is a high-severity vulnerability that can lead to a crash of the Suricata service.
To fix CVE-2024-38536, upgrade Suricata to version 7.0.6 or later.
CVE-2024-38536 is caused by a memory allocation failure when the http.memcap limit is reached.
Suricata versions prior to 7.0.6 are affected by CVE-2024-38536.
CVE-2024-38536 is a memory management vulnerability that results in a null pointer dereference leading to a crash.