Debian Suricata vulnerabilities
81 known vulnerabilities affecting debian/suricata.
Total CVEs
81
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH45MEDIUM14LOW15
Vulnerabilities
Page 4 of 5
CVE-2024-55628P3HIGHCVSS 7.5fixed in suricata 1:7.0.8-1 (forky)2024
CVE-2024-55628 [HIGH] CVE-2024-55628: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to very large DNS log records. While there are limits in place, they were too generous. The
debian
CVE-2019-10051P3HIGHCVSS 7.5fixed in suricata 1:4.1.4-1 (bookworm)2019
CVE-2019-10051 [HIGH] CVE-2019-10051: suricata - An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk ...
An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the program enters an smb/files.rs error condition and crashes.
Scope: local
bookworm: resolved (fixed in 1:4.1.4-1)
bullseye: resolved (fixed in 1:4.1.4-1)
forky: resolved (fixed in 1:4.1.4-1)
sid: resolved (fixed in 1:4.
debian
CVE-2017-15377P3LOWCVSS 7.5fixed in suricata 1:4.0.0-1 (bookworm)2017
CVE-2017-15377 [HIGH] CVE-2017-15377: suricata - In Suricata before 4.x, it was possible to trigger lots of redundant checks on t...
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engine-content-inspection.c. The search engine doesn't stop when it should after no match is found; instead, it stops only upon reaching inspection-recursion-limit (3000 by
debian
CVE-2019-10054P3HIGHCVSS 7.5fixed in suricata 1:4.1.4-1 (bookworm)2019
CVE-2019-10054 [HIGH] CVE-2019-10054: suricata - An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 ...
An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memory access and the program crashes within the nfs/nfs3.rs file.
Scope: local
bookworm: resolved (fixed in 1:4.1.4-1)
bullseye: resolved (fixed in 1:4.1.4-1)
forky: resolved (fixed in 1:4.1.4-1)
sid: resolved (fixed in 1
debian
CVE-2019-10056P3HIGHCVSS 7.5fixed in suricata 1:4.1.4-1 (bookworm)2019
CVE-2019-10056 [HIGH] CVE-2019-10056: suricata - An issue was discovered in Suricata 4.1.3. The code mishandles the case of sendi...
An issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type, such that the function DecodeEthernet in decode-ethernet.c is executed a second time. At this point, the algorithm cuts the first part of the packet and doesn't determine the current length. Specifically, if the packet is exactly 28 long, in the
debian
CVE-2019-10055P3HIGHCVSS 7.5fixed in suricata 1:4.1.4-1 (bookworm)2019
CVE-2019-10055 [HIGH] CVE-2019-10055: suricata - An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks ...
An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file.
Scope: local
bookworm: resolved (fixed in 1:4.1.4-1)
bullseye: resolved (fixed in 1:4.1.4-1)
forky: resolved (fixed in 1:4.1.4-1)
sid: resolved (fixed in 1:4.1.4-1)
trixie: resolved (fixed in 1:4.1
debian
CVE-2015-0928P4HIGHCVSS 7.5fixed in suricata 2.0.7-1 (bookworm)2015
CVE-2015-0928 [HIGH] CVE-2015-0928: suricata - libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer...
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
Scope: local
bookworm: resolved (fixed in 2.0.7-1)
bullseye: resolved (fixed in 2.0.7-1)
forky: resolved (fixed in 2.0.7-1)
sid: resolved (fixed in 2.0.7-1)
trixie: resolved (fixed in 2.0.7-1)
debian
CVE-2017-7177P4HIGHCVSS 7.5fixed in suricata 3.2.1-1 (bookworm)2017
CVE-2017-7177 [HIGH] CVE-2017-7177: suricata - Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack o...
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
Scope: local
bookworm: resolved (fixed in 3.2.1-1)
bullseye: resolved (fixed in 3.2.1-1)
forky: resolved (fixed in 3.2.1-1)
sid: resolved (fixed in 3.2.1-1)
trixie: resolved (fixed in 3.2.1-1)
debian
CVE-2024-24568P4LOWCVSS 5.3fixed in suricata 1:7.0.3-1 (forky)2024
CVE-2024-24568 [MEDIUM] CVE-2024-24568: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:7.0.3-1)
sid: resolved (fixed in 1:
debian
CVE-2026-22263P4LOWCVSS 5.3fixed in suricata 1:8.0.3-1 (forky)2026
CVE-2026-22263 [MEDIUM] CVE-2026-22263: suricata - Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and pri...
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:8.0.3-1)
sid: resolved (fixed in 1
debian
CVE-2026-22261P4LOWCVSS 3.7fixed in suricata 1:8.0.3-1 (forky)2026
CVE-2026-22261 [LOW] CVE-2026-22261: suricata - Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.1...
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in the eve configuration. The setting is disabled by default.
Scope: local
bookworm: open
debian
CVE-2024-32867P4MEDIUMCVSS 5.3fixed in suricata 1:7.0.5-1 (forky)2024
CVE-2024-32867 [MEDIUM] CVE-2024-32867: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in
debian
CVE-2016-10728P4MEDIUMCVSS 5.3fixed in suricata 3.1.2-1 (bookworm)2016
CVE-2016-10728 [MEDIUM] CVE-2016-10728: suricata - An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is r...
An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.
Scope: local
bookworm: resolved (fixed in 3.1.2-1)
bullseye: resolved
debian
CVE-2024-45796P4MEDIUMCVSS 5.3fixed in suricata 1:6.0.1-3+deb11u1 (bullseye)2024
CVE-2024-45796 [MEDIUM] CVE-2024-45796: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, a logic error during fragment reassembly can lead to failed reassembly for valid traffic. An attacker could craft packets to trigger this behavior.This issue has been addressed in 7.0.7.
Scope: local
bookworm: open
bullseye
debian
CVE-2014-6603P4MEDIUMCVSS 5.0fixed in suricata 2.0.4-1 (bookworm)2014
CVE-2014-6603 [MEDIUM] CVE-2014-6603: suricata - The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2...
The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.
Scope: local
bookworm: resolved (fixed in 2.0.4-1)
bullseye: resolved
debian
CVE-2025-29918P4MEDIUMCVSS 6.2fixed in suricata 1:6.0.1-3+deb11u1 (bullseye)2025
CVE-2025-29918 [MEDIUM] CVE-2025-29918: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an infinite loop when negated PCRE is used. Packet processing thread becomes stuck in infinite loop limiting visibility and availability in inline mode. This vulnerability is fixed in 7.0.9.
Scope: local
bo
debian
CVE-2025-29916P4MEDIUMCVSS 6.2fixed in suricata 1:7.0.9-1 (forky)2025
CVE-2025-29916 [MEDIUM] CVE-2025-29916: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the `hashsize` to use. This size setting isn't properly limited, so the hash table allocation can be large. Untrusted rules can lead to large memory allocations, potentially leading to denial of
debian
CVE-2025-29917P4MEDIUMCVSS 6.2fixed in suricata 1:7.0.9-1 (forky)2025
CVE-2025-29917 [MEDIUM] CVE-2025-29917: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The bytes setting in the decode_base64 keyword is not properly limited. Due to this, signatures using the keyword and setting can cause large memory allocations of up to 4 GiB per thread. This vulnerability is fixed in 7.0.9.
Scope: local
bookworm
debian
CVE-2024-55626P4LOWCVSS 3.3fixed in suricata 1:6.0.1-3+deb11u1 (bullseye)2024
CVE-2024-55626 [LOW] CVE-2024-55626: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup. The issue has been addressed in Suricata 7.0.8.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:6.0.1-3+deb11u1)
for
debian
CVE-2013-5919P4MEDIUMCVSS 5.0fixed in suricata 2.0-1 (bookworm)2013
CVE-2013-5919 [MEDIUM] CVE-2013-5919: suricata - Suricata before 1.4.6 allows remote attackers to cause a denial of service (cras...
Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
Scope: local
bookworm: resolved (fixed in 2.0-1)
bullseye: resolved (fixed in 2.0-1)
forky: resolved (fixed in 2.0-1)
sid: resolved (fixed in 2.0-1)
trixie: resolved (fixed in 2.0-1)
debian