CVE-2024-37151

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-07-11 15:15

Updated : 2024-07-12 18:46


NVD link : CVE-2024-37151

Mitre link : CVE-2024-37151

CVE.ORG link : CVE-2024-37151


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions