CVE-2024-45796

NameCVE-2024-45796
DescriptionSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, a logic error during fragment reassembly can lead to failed reassembly for valid traffic. An attacker could craft packets to trigger this behavior.This issue has been addressed in 7.0.7.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4103-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
suricata (PTS)bullseye1:6.0.1-3vulnerable
bullseye (security)1:6.0.1-3+deb11u1fixed
trixie1:7.0.10-1+deb13u4fixed
forky, sid1:8.0.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
suricatasourcebullseye1:6.0.1-3+deb11u1DLA-4103-1
suricatasource(unstable)1:7.0.7-1

Notes

https://github.com/OISF/suricata/security/advisories/GHSA-mf6r-3xp2-v7xg
https://redmine.openinfosecfoundation.org/issues/7067

Search for package or bug name: Reporting problems