First published: Wed Oct 16 2024(Updated: )
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborting with a panic. This issue has been addressed in 7.0.7. One may disable ja4 as a workaround.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OISF Suricata | <7.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47522 has not been assigned a specific severity rating but can lead to system panic, which may impact availability.
To fix CVE-2024-47522, upgrade to Suricata version 7.0.7 or later.
CVE-2024-47522 can cause Suricata to abort with a panic due to invalid ALPN in TLS/QUIC traffic.
Suricata versions prior to 7.0.7 are affected by CVE-2024-47522.
Any system running Suricata version before 7.0.7 with JA4 matching/logging enabled is vulnerable to CVE-2024-47522.