CVE-2024-45795: Suricata detect/datasets: reachable assertion with unimplemented rule option
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, rules using datasets with the non-functional / unimplemented "unset" option can trigger an assertion during traffic parsing, leading to denial of service. This issue is addressed in 7.0.7. As a workaround, use only trusted and well tested rulesets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45795?
CVE-2024-45795 has a severity that can lead to denial of service due to an assertion failure during traffic parsing.
How do I fix CVE-2024-45795?
To fix CVE-2024-45795, upgrade Suricata to version 7.0.7 or later.
What systems are affected by CVE-2024-45795?
CVE-2024-45795 affects Suricata versions prior to 7.0.7.
What issues can arise from CVE-2024-45795?
CVE-2024-45795 can trigger an assertion that results in a denial of service during network traffic parsing.
Can I continue using Suricata if I'm on a version prior to 7.0.7?
It is not recommended to use Suricata versions prior to 7.0.7 due to the vulnerability identified in CVE-2024-45795.