cbcvebase.

Debian Suricata vulnerabilities

81 known vulnerabilities affecting debian/suricata.

Total CVEs
81
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH45MEDIUM14LOW15

Vulnerabilities

Page 2 of 5
CVE-2026-22260P3LOWCVSS 7.5fixed in suricata 1:8.0.3-1 (forky)2026
CVE-2026-22260 [HIGH] CVE-2026-22260: suricata - Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and pri... Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As a workaround, use default values for `request-body-limit` and `response-body-limit`. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:8.0.3-1) sid: resolved (
debian
CVE-2025-64332P3HIGHCVSS 7.5fixed in suricata 1:8.0.2-1 (forky)2025
CVE-2025-64332 [HIGH] CVE-2025-64332: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform... Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow that causes Suricata to crash can occur if SWF decompression is enabled. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling S
debian
CVE-2025-64330P3HIGHCVSS 7.5fixed in suricata 1:8.0.2-1 (forky)2025
CVE-2025-64330 [HIGH] CVE-2025-64330: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform... Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a single byte read heap overflow when logging the verdict in eve.alert and eve.drop records can lead to crashes. This requires the per packet alert queue to be filled with alerts and then followed
debian
CVE-2025-64344P3HIGHCVSS 7.5fixed in suricata 1:8.0.2-1 (forky)2025
CVE-2025-64344 [HIGH] CVE-2025-64344: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform... Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large
debian
CVE-2025-64333P3HIGHCVSS 7.5fixed in suricata 1:8.0.2-1 (forky)2025
CVE-2025-64333 [HIGH] CVE-2025-64333: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform... Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a large HTTP content type, when logged can cause a stack overflow crashing Suricata. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves limiting stream.
debian
CVE-2025-64331P3HIGHCVSS 7.5fixed in suricata 1:8.0.2-1 (forky)2025
CVE-2025-64331 [HIGH] CVE-2025-64331: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform... Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow can occur on large HTTP file transfers if the user has increased the HTTP response body limit and enabled the logging of printable http bodies. This issue has been patched in vers
debian
CVE-2019-15699P3LOWCVSS 9.1fixed in suricata 1:4.1.5-1 (bookworm)2019
CVE-2019-15699 [CRITICAL] CVE-2019-15699: suricata - An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a c... An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet. Scope: local bookworm:
debian
CVE-2024-55627P3MEDIUMCVSS 5.9fixed in suricata 1:7.0.8-1 (forky)2024
CVE-2024-55627 [MEDIUM] CVE-2024-55627: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an... Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead to a very large buffer overflow while being zero-filled during initialization with memset due to an unsigned integer underflow. The issue has been addressed in Suricata 7.0.8. Scope: local bo
debian
CVE-2019-10053P3CRITICALCVSS 9.8fixed in suricata 1:4.1.4-1 (bookworm)2019
CVE-2019-10053 [CRITICAL] CVE-2019-10053: suricata - An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the func... An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow. Scope: local bookworm: resolved (fixed in 1:4.1.4-1) bullseye: resolved (fixed in 1:4.1.
debian
CVE-2024-32664P3MEDIUMCVSS 5.3fixed in suricata 1:7.0.5-1 (forky)2024
CVE-2024-32664 [MEDIUM] CVE-2024-32664: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an... Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets can cause a limited buffer overflow. This vulnerability is fixed in 7.0.5 and 6.0.19. Workarounds include not use rules with `base64_decode` keyword with `bytes` option with value 1,
debian
CVE-2024-23836P3HIGHCVSS 7.5fixed in suricata 1:7.0.3-1 (forky)2024
CVE-2024-23836 [HIGH] CVE-2024-23836: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an... Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft traffic to cause Suricata to use far more CPU and memory for processing the traffic than needed, which can lead to extreme slow downs and denial of service. This vulnerability is patched in 6
debian
CVE-2024-37151P3MEDIUMCVSS 5.3fixed in suricata 1:6.0.1-3+deb11u1 (bullseye)2024
CVE-2024-37151 [MEDIUM] CVE-2024-37151: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an... Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem. Sco
debian
CVE-2026-31933P3HIGHCVSS 7.5fixed in suricata 1:8.0.4-1 (forky)2026
CVE-2026-31933 [HIGH] CVE-2026-31933: suricata - Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.... Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:8.0.4-1) sid: resolved (fixed in 1:8.0.4-1) trixie: open
debian
CVE-2026-31935P3HIGHCVSS 7.5fixed in suricata 1:8.0.4-1 (forky)2026
CVE-2026-31935 [HIGH] CVE-2026-31935: suricata - Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.... Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4. Scope: local bookworm: open bullseye: open forky: resolved (fixed in
debian
CVE-2019-18625P3HIGHCVSS 7.5fixed in suricata 1:5.0.2-1 (bookworm)2019
CVE-2019-18625 [HIGH] CVE-2019-18625: suricata - An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any t... An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. After the TCP SYN packet, it is possible to inject a RST ACK and a FIN ACK packet with a bad TCP Timestamp option. The client will ignore the RST ACK and the FIN ACK packets because of the bad TCP Timestamp option.
debian
CVE-2023-35852P3HIGHCVSS 7.5fixed in suricata 1:6.0.1-3+deb11u1 (bullseye)2023
CVE-2023-35852 [HIGH] CVE-2023-35852: suricata - In Suricata before 6.0.13 (when there is an adversary who controls an external s... In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trigger absolute or relative directory traversal, and lead to write access to a local filesystem. This is addressed in 6.0.13 by requiring allow-absolute-filenames and allow-write (in the datasets rules configuration secti
debian
CVE-2025-53538P3HIGHCVSS 7.5fixed in suricata 1:7.0.11-1 (forky)2025
CVE-2025-53538 [HIGH] CVE-2025-53538: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform... Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.0.10 and below and 8.0.0-beta1 through 8.0.0-rc1, mishandling of data on HTTP2 stream 0 can lead to uncontrolled memory usage, leading to loss of visibility. Workarounds include disabling the HTTP/2 parser, and using a
debian
CVE-2026-31932P3HIGHCVSS 7.5fixed in suricata 1:8.0.4-1 (forky)2026
CVE-2026-31932 [HIGH] CVE-2026-31932: suricata - Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.... Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:8.0.4-1) sid: resolved (fixed in 1:8.0.4-1) trixie: open
debian
CVE-2019-1010251P3LOWCVSS 7.5fixed in suricata 1:4.1.2-2 (bookworm)2019
CVE-2019-1010251 [HIGH] CVE-2019-1010251: suricata - Open Information Security Foundation Suricata prior to version 4.1.2 is affected... Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commit
debian
CVE-2018-14568P3HIGHCVSS 7.5fixed in suricata 1:4.0.5-1 (bookworm)2018
CVE-2018-14568 [HIGH] CVE-2018-14568: suricata - Suricata before 4.0.5 stops TCP stream inspection upon a TCP RST from a server. ... Suricata before 4.0.5 stops TCP stream inspection upon a TCP RST from a server. This allows detection bypass because Windows TCP clients proceed with normal processing of TCP data that arrives shortly after an RST (i.e., they act as if the RST had not yet been received). Scope: local bookworm: resolved (fixed in 1:4.0.5-1) bullseye: resolved (fixed in 1:4.0.5-1) fo
debian
Debian Suricata vulnerabilities | cvebase