Debian Suricata vulnerabilities
81 known vulnerabilities affecting debian/suricata.
Total CVEs
81
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH45MEDIUM14LOW15
Vulnerabilities
Page 1 of 5
CVE-2018-18956P2HIGHCVSS 7.5Exploitedfixed in suricata 1:4.0.6-1 (bookworm)2018
CVE-2018-18956 [HIGH] CVE-2018-18956: suricata - The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0....
The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the wild in November 2018.
Scope: local
bookworm: resolved (fixed in 1:4.0.6-1)
bullseye: resolved (fixed in 1:4.0.6-1)
forky: resolved (fixed in 1:4.
debian
CVE-2018-6794P3MEDIUMCVSS 5.3PoCfixed in suricata 1:4.0.4-1 (bookworm)2018
CVE-2018-6794 [MEDIUM] CVE-2018-6794: suricata - Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in dete...
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-way handshake is complete, then the data sent by the malicious server will be accepted by web clients such as a web browser or Linux CLI utilities, but ignored by Suricata IDS signatures. T
debian
CVE-2015-8954P3CRITICALCVSS 9.8fixed in suricata 2.0.6-1 (bookworm)2015
CVE-2015-8954 [CRITICAL] CVE-2015-8954: suricata - The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the fi...
The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.
Scope: local
bookworm: resolved (fixed in 2.0.6-1)
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.
debian
CVE-2026-22262P3MEDIUMCVSS 5.9fixed in suricata 1:8.0.3-1 (forky)2026
CVE-2026-22262 [MEDIUM] CVE-2026-22262: suricata - Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack bu...
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use rules with datasets `save` nor `state` options.
Scope: local
bookw
debian
CVE-2021-37592P3CRITICALCVSS 9.8fixed in suricata 1:6.0.4-1 (bookworm)2021
CVE-2021-37592 [CRITICAL] CVE-2021-37592: suricata - Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with ...
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.
Scope: local
bookworm: resolved (fixed in 1:6.0.4-1)
bullseye: open
forky: resolved (fixed in 1:6.0.4-1)
sid: resolved (fixed in 1:6.0.4-1)
trixie: resolved (fixed in 1:6.0.4-1)
debian
CVE-2023-35853P3CRITICALCVSS 9.8fixed in suricata 1:6.0.13-1 (forky)2023
CVE-2023-35853 [CRITICAL] CVE-2023-35853: suricata - In Suricata before 6.0.13, an adversary who controls an external source of Lua r...
In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:6.0.13-1)
sid: resolved (fixed in 1:6.0.13-1)
trixie: resol
debian
CVE-2026-22264P3HIGHCVSS 7.4fixed in suricata 1:8.0.3-1 (forky)2026
CVE-2026-22264 [HIGH] CVE-2026-22264: suricata - Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14...
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not run untrusted rulesets or run with less than 65536 signatures that can match on
debian
CVE-2018-10243P3CRITICALCVSS 9.8fixed in libhtp 1:0.5.28-1 (bookworm)2018
CVE-2018-10243 [CRITICAL] CVE-2018-10243: libhtp - htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote a...
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
Scope: local
bookworm: resolved (fixed in 1:0.5.28-1)
bullseye: resolved (fixed in 1:0.5.28-1)
forky: resolved (fixed in 1:0.5.28-1)
sid: resolved (fixed in 1:0.5.28-1)
trixie: resolved (fixed in 1:0.5
debian
CVE-2019-18792P3CRITICALCVSS 9.1fixed in suricata 1:5.0.2-1 (bookworm)2019
CVE-2019-18792 [CRITICAL] CVE-2019-18792: suricata - An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tc...
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the PUSH ACK packet we want to bypass. The PUSH ACK packet (containing the data) will be ignored by Suricata because it overlaps the FIN packet (the sequence and ack nu
debian
CVE-2019-16411P3LOWCVSS 9.8fixed in suricata 1:4.1.5-1 (bookworm)2019
CVE-2019-16411 [CRITICAL] CVE-2019-16411: suricata - An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that...
An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in decode-ipv4.c tries to access a memory region that is not allocated. There is a check for o->len data + 3)" places one beyond the 3 bytes, because the code should have been "flag = *(o->data + 1)" instead.
Scope: lo
debian
CVE-2024-23839P3LOWCVSS 7.1fixed in suricata 1:7.0.3-1 (forky)2024
CVE-2024-23839 [HIGH] CVE-2024-23839: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.requ
debian
CVE-2021-45098P3HIGHCVSS 7.5fixed in suricata 1:6.0.4-1 (bookworm)2021
CVE-2021-45098 [HIGH] CVE-2021-45098: suricata - An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade...
An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden URL.
debian
CVE-2019-16410P3LOWCVSS 9.1fixed in suricata 1:4.1.5-1 (bookworm)2019
CVE-2019-16410 [CRITICAL] CVE-2019-16410: suricata - An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 p...
An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a memory region that is not allocated, because of a lack of header_len checking.
Scope: local
bookworm: resolved (fixed in 1:4.1.5-1)
bullseye: resolved (fixed in 1:4.1.5-1)
forky: resolved (fixed in 1:4.1.5-1)
sid:
debian
CVE-2018-10244P3CRITICALCVSS 9.8fixed in suricata 1:4.0.5-1 (bookworm)2018
CVE-2018-10244 [CRITICAL] CVE-2018-10244: suricata - Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A ...
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check.
Scope: local
bookworm: resolved (fixed in 1:4.0.5-1)
bullseye: resolved (fixed in 1:4.0.5-1)
forky: resolved (f
debian
CVE-2025-59147P3HIGHCVSS 7.5fixed in suricata 1:8.0.1-1 (forky)2025
CVE-2025-59147 [HIGH] CVE-2025-59147: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform...
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 7.0.11 and below, as well as 8.0.0, are vulnerable to detection bypass when crafted traffic sends multiple SYN packets with different sequence numbers within the same flow tuple, which can cause Suricata to fail to pick up
debian
CVE-2025-29915P3HIGHCVSS 7.5fixed in suricata 1:7.0.9-1 (forky)2025
CVE-2025-29915 [HIGH] CVE-2025-29915: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The AF_PACKET defrag option is enabled by default and allows AF_PACKET to re-assemble fragmented packets before reaching Suricata. However the default packet size in Suricata is based on the network interface MTU which leads to Suricata seeing trunc
debian
CVE-2024-55629P3HIGHCVSS 7.5fixed in suricata 1:7.0.8-1 (forky)2024
CVE-2024-55629 [HIGH] CVE-2024-55629: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, TCP streams with TCP urgent data (out of band data) can lead to Suricata analyzing data differently than the applications at the TCP endpoints, leading to possible evasions. Suricata 7.0.8 includes options to allow users to configure
debian
CVE-2026-22259P3HIGHCVSS 7.5fixed in suricata 1:8.0.3-1 (forky)2026
CVE-2026-22259 [HIGH] CVE-2026-22259: suricata - Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.1...
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a
debian
CVE-2026-22258P3HIGHCVSS 7.5fixed in suricata 1:8.0.3-1 (forky)2026
CVE-2026-22258 [HIGH] CVE-2026-22258: suricata - Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.1...
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB are also vulnerable. DCERPC/TCP in the default configuration should no
debian
CVE-2024-55605P3HIGHCVSS 7.5fixed in suricata 1:7.0.8-1 (forky)2024
CVE-2024-55605 [HIGH] CVE-2024-55605: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, to_uppercase, strip_whitespace, compress_whitespace, dotprefix, header_lowercase, strip_pseudo_headers, url_decode, or xor transform can lead to a stack overflow causing Suricata to crash. Th
debian
1 / 5Next →