CyberRota Analysis
AI-GeneratedSuricata versions 8.0.0 to 8.0.6 are vulnerable due to improper handling of DNS-over-HTTP/2 DATA frames, which can lead to excessive CPU usage and potential denial of service as the internal buffer retains previously processed data. This vulnerability can degrade packet processing and monitoring visibility, making it critical for organizations using Suricata for network security to prioritize upgrading to version 8.0.6 or later. Network security teams should assess their environments promptly to mitigate the risk associated with this issue.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing all prior contents to be processed again, producing quadratic CPU complexity, degraded packet processing, loss of monitoring visibility, or denial of service. This issue is fixed in version 8.0.6.
Related CVEs
Other vulnerabilities affecting the same vendor(s)