Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 925747 (CVE-2024-23835, CVE-2024-23836, CVE-2024-23839, CVE-2024-24568) - <net-analyzer/suricata-7.0.3: multiple vulnerabilities
Summary: <net-analyzer/suricata-7.0.3: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2024-23835, CVE-2024-23836, CVE-2024-23839, CVE-2024-24568
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Marek Szuba
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2024-02-29 10:04 UTC by Marek Szuba
Modified: 2024-03-01 05:09 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marek Szuba archtester gentoo-dev 2024-02-29 10:04:02 UTC
1. Suricata:

* CVE-2024-23839 - Critical severity

Specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword.

* CVE-2024-23836 - Critical severity

An attacker can craft traffic to cause Suricata to use far more CPU and memory for processing the traffic than needed, which can lead to extreme slow downs and denial of service.

* CVE-2024-23835 - High severity

Excessive memory use during pgsql parsing could lead to OOM-related crashes.

* CVE-2024-24568 - Moderate severity

Rules inspecting HTTP2 headers can get bypassed by crafted traffic.


2. libHTP (which we package separately but which also comes bundled with Suricata tarballs):

* CVE-2024-23837 - Critical severity

Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service.

* * *

No vulnerable version of either package left in the tree.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2024-03-01 05:06:21 UTC
Thanks for reporting. Please separate unique packages into unique bugs when there's no intersection between the sets of vulnerabilities for each package.