Debian Suricata vulnerabilities
81 known vulnerabilities affecting debian/suricata.
Total CVEs
81
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH45MEDIUM14LOW15
Vulnerabilities
Page 3 of 5
CVE-2024-38535P3HIGHCVSS 7.5fixed in suricata 1:7.0.6-1 (forky)2024
CVE-2024-38535 [HIGH] CVE-2024-38535: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.6-1)
sid: resolved (fixed in 1:7.0.6-1)
trixie: resolved (fixed in 1:7.0.6-1)
debian
CVE-2024-38534P3HIGHCVSS 7.5fixed in suricata 1:7.0.6-1 (forky)2024
CVE-2024-38534 [HIGH] CVE-2024-38534: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within a flow. Upgrade to 7.0.6. Set a limited stream.reassembly.depth to reduce the issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.6-1)
sid: resol
debian
CVE-2024-28870P3HIGHCVSS 7.5fixed in suricata 1:7.0.4-1 (forky)2024
CVE-2024-28870 [HIGH] CVE-2024-28870: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community. When parsing an overly long SSH banner, Suricata can use excessive CPU resources, as well as cause excessive logging volume in alert records. This issue has been patched in versions 6.0.17 and 7.0.4.
debian
CVE-2026-31937P3HIGHCVSS 7.5fixed in suricata 1:8.0.1-1 (forky)2026
CVE-2026-31937 [HIGH] CVE-2026-31937: suricata - Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, ineffici...
Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in version 7.0.15.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:8.0.1-1)
sid: resolved (fixed in 1:8.0.1-1)
trixie: open
debian
CVE-2026-31931P3HIGHCVSS 7.5fixed in suricata 1:8.0.4-1 (forky)2026
CVE-2026-31931 [HIGH] CVE-2026-31931: suricata - Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before vers...
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:8.0.4-1)
sid: resolved (fixed in 1:8.0.4-1)
trixie: open
debian
CVE-2024-47188P3HIGHCVSS 7.5fixed in suricata 1:7.0.7-1 (forky)2024
CVE-2024-47188 [HIGH] CVE-2024-47188: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to byte-range tracking having predictable hash table behavior. This can lead to an attacker forcing lots of data into a single hash bucket, leading to severe perform
debian
CVE-2019-10052P3HIGHCVSS 7.5fixed in suricata 1:4.1.4-1 (bookworm)2019
CVE-2019-10052 [HIGH] CVE-2019-10052: suricata - An issue was discovered in Suricata 4.1.3. If the network packet does not have t...
An issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to access a part of a DHCP packet. At this point, the Rust environment runs into a panic in parse_clientid_option in the dhcp/parser.rs file.
Scope: local
bookworm: resolved (fixed in 1:4.1.4-1)
bullseye: resolved (fixed in 1:4.1.4-1)
forky: resolved (f
debian
CVE-2021-35063P3HIGHCVSS 7.5fixed in suricata 1:6.0.1-3 (bookworm)2021
CVE-2021-35063 [HIGH] CVE-2021-35063: suricata - Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."
Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."
Scope: local
bookworm: resolved (fixed in 1:6.0.1-3)
bullseye: resolved (fixed in 1:6.0.1-3)
forky: resolved (fixed in 1:6.0.1-3)
sid: resolved (fixed in 1:6.0.1-3)
trixie: resolved (fixed in 1:6.0.1-3)
debian
CVE-2024-32663P3HIGHCVSS 7.5fixed in suricata 1:6.0.1-3+deb11u1 (bullseye)2024
CVE-2024-32663 [HIGH] CVE-2024-32663: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a small amount of HTTP/2 traffic can lead to Suricata using a large amount of memory. The issue has been addressed in Suricata 7.0.5 and 6.0.19. Workarounds include disabling the HTTP/2 parser and reducing `app-layer.proto
debian
CVE-2024-23835P3LOWCVSS 7.5fixed in suricata 1:7.0.3-1 (forky)2024
CVE-2024-23835 [HIGH] CVE-2024-23835: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround, users can disable the pgsql app layer parser.
Scope: local
bookworm: resolved
bullseye: resol
debian
CVE-2024-47522P3HIGHCVSS 7.5fixed in suricata 1:7.0.7-1 (forky)2024
CVE-2024-47522 [HIGH] CVE-2024-47522: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborting with a panic. This issue has been addressed in 7.0.7. One may disable ja4 as a workaround.
Scope: local
bookworm: open
bullse
debian
CVE-2024-45795P3HIGHCVSS 7.5fixed in suricata 1:7.0.7-1 (forky)2024
CVE-2024-45795 [HIGH] CVE-2024-45795: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, rules using datasets with the non-functional / unimplemented "unset" option can trigger an assertion during traffic parsing, leading to denial of service. This issue is addressed in 7.0.7. As a workaround, use only trusted an
debian
CVE-2025-64335P3LOWCVSS 7.5fixed in suricata 1:8.0.2-1 (forky)2025
CVE-2025-64335 [HIGH] CVE-2025-64335: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform...
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entr
debian
CVE-2025-64334P3LOWCVSS 7.5fixed in suricata 1:8.0.2-1 (forky)2025
CVE-2025-64334 [HIGH] CVE-2025-64334: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform...
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting resp
debian
CVE-2024-47187P3HIGHCVSS 7.5fixed in suricata 1:7.0.7-1 (forky)2024
CVE-2024-47187 [HIGH] CVE-2024-47187: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset file loading to use excessive time to load, as well as runtime performance issues during
debian
CVE-2026-31934P3HIGHCVSS 7.5fixed in suricata 1:8.0.4-1 (forky)2026
CVE-2026-31934 [HIGH] CVE-2026-31934: suricata - Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before vers...
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This issue has been patched in version 8.0.4.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:8.0.4-1)
sid: resolved (fixed
debian
CVE-2019-10050P3HIGHCVSS 7.5fixed in suricata 1:4.1.4-1 (bookworm)2019
CVE-2019-10050 [HIGH] CVE-2019-10050: suricata - A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the i...
A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a packet of source address and destination address plus the correct type field and the right number for shim, an attacker can manipulate the control flow, such that the condition to leave the loop is true. After leaving t
debian
CVE-2024-38536P3HIGHCVSS 7.5fixed in suricata 1:7.0.6-1 (forky)2024
CVE-2024-38536 [HIGH] CVE-2024-38536: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads to a NULL-ptr reference leading to a crash. Upgrade to 7.0.6.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.6-1)
sid: resolved (fixed in 1:7.0.6-1)
tri
debian
CVE-2018-10242P3HIGHCVSS 7.5fixed in suricata 1:4.0.5-1 (bookworm)2018
CVE-2018-10242 [HIGH] CVE-2018-10242: suricata - Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malf...
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.
Scope: local
bookworm: resolved (fixed in 1:4.0.5-1)
bullseye: resolved (fixed in 1:4.0.5-1)
forky: resolved (fixed in 1:4.0.5-1)
sid: resolved (
debian
CVE-2019-1010279P3LOWCVSS 7.5fixed in suricata 1:4.1.3-1 (bookworm)2019
CVE-2019-1010279 [HIGH] CVE-2019-1010279: suricata - Open Information Security Foundation Suricata prior to version 4.1.3 is affected...
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed sequence of network packets. The component is: detect.c (https://github.com/OISF/suricata/pull/3625/commits/d8634daf74c882356659addb65fb142b738a186b)
debian