CVE-2024-47522: Suricata ja4: invalid alpn leads to panic
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborting with a panic. This issue has been addressed in 7.0.7. One may disable ja4 as a workaround.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47522?
CVE-2024-47522 has not been assigned a specific severity rating but can lead to system panic, which may impact availability.
How do I fix CVE-2024-47522?
To fix CVE-2024-47522, upgrade to Suricata version 7.0.7 or later.
What is the impact of CVE-2024-47522?
CVE-2024-47522 can cause Suricata to abort with a panic due to invalid ALPN in TLS/QUIC traffic.
Which versions of Suricata are affected by CVE-2024-47522?
Suricata versions prior to 7.0.7 are affected by CVE-2024-47522.
What systems are vulnerable to CVE-2024-47522?
Any system running Suricata version before 7.0.7 with JA4 matching/logging enabled is vulnerable to CVE-2024-47522.