CVE-2024-23836

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 26, 2024
Updated: Dec 19, 2024
CWE ID 770

Summary

CVE-2024-23836 is a vulnerability affecting Suricata, an open-source network Intrusion Detection System (IDS) and Intrusion Prevention System (IPS). Prior to versions 6.0.16 and 7.0.3, Suricata is susceptible to excessive CPU and memory usage when processing maliciously crafted traffic. This can lead to severe slowdowns and potential denial of service. The vulnerability is addressed in versions 6.0.16 and 7.0.3. As a workaround, users can disable the affected protocol app-layer parser in the yaml file or reduce the `stream.reassembly.depth` value to mitigate the issue's severity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • OISF (The Open Information Security Foundation) Suricata
  • Fedora Operating System

Affected Vendors

  • Fedora Project