CVE-2024-55628

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 6, 2025
CWE ID 779
CWE ID 405

Summary

CVE-2024-55628 affects Suricata, a popular network Intrusion Detection System and Security Monitoring engine. The vulnerability stems from an issue with DNS resource name compression, which allows small DNS messages to contain unusually large hostnames. These oversized hostnames, though restricted, can result in costly decoding processes and expansive DNS log records. Fortunately, this issue has been resolved in Suricata version 7.0.8.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share