CVE-2024-55626: Suricata oversized bpf file can lead to buffer overflow
Published Jan 6, 2025
·Updated
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup. The issue has been addressed in Suricata 7.0.8.
Affected Software
2 affected components
Suricata Suricata<7.0.8
OISF Suricata<7.0.8
Remediation
Event History
Jan 6, 2025
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55626?
CVE-2024-55626 has a high severity due to the potential for a buffer overflow leading to Denial of Service or code execution.
2
How do I fix CVE-2024-55626?
To fix CVE-2024-55626, upgrade Suricata to version 7.0.8 or later.
3
Which versions of Suricata are affected by CVE-2024-55626?
CVE-2024-55626 affects Suricata versions prior to 7.0.8.
4
What are the potential impacts of CVE-2024-55626?
The potential impacts of CVE-2024-55626 include system crashes or execution of arbitrary code during Suricata startup.
5
What component of Suricata does CVE-2024-55626 affect?
CVE-2024-55626 affects the startup process of Suricata when a large BPF filter file is provided.