CVE-2024-55628: Suricata oversized resource names utilizing DNS name compression can lead to resource starvation
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to very large DNS log records. While there are limits in place, they were too generous. The issue has been addressed in Suricata 7.0.8.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55628?
CVE-2024-55628 is classified as a medium severity vulnerability due to its potential impact on performance during DNS message processing.
How do I fix CVE-2024-55628?
To fix CVE-2024-55628, upgrade Suricata to version 7.0.8 or later.
What versions of Suricata are affected by CVE-2024-55628?
CVE-2024-55628 affects Suricata versions prior to 7.0.8.
What kind of vulnerability is CVE-2024-55628?
CVE-2024-55628 is a vulnerability related to DNS resource name compression that can lead to performance issues.
Is CVE-2024-55628 exploitable remotely?
Yes, CVE-2024-55628 can be exploited remotely since it involves processing DNS messages.