Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup. The issue has been addressed in Suricata 7.0.8.
The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
Link | Tags |
---|---|
https://github.com/OISF/suricata/security/advisories/GHSA-wmg4-jqx5-4h9v | vendor advisory |
https://github.com/OISF/suricata/commit/dd71ef0af222a566e54dfc479dd1951dd17d7ceb | patch |
https://redmine.openinfosecfoundation.org/issues/7366 | permissions required |