Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-31931

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.

A flaw was found in Suricata, a network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring (NSM) engine. An attacker could trigger a null dereference by using the "tls.alpn" rule keyword, causing the Suricata engine to crash. This vulnerability leads to a Denial of Service (DoS).

Отчет

Important: Suricata is vulnerable to a denial of service when processing network traffic with rules that utilize the tls.alpn keyword. An attacker can trigger a null dereference, causing the Suricata engine to crash. This issue affects Suricata versions 8.0.0 through 8.0.3.

Меры по смягчению последствий

To mitigate this issue, avoid using the 'tls.alpn' rule keyword in Suricata configurations. If Suricata crashes due to this vulnerability, restarting the service may temporarily restore functionality. Ensure that Suricata configurations do not include the 'tls.alpn' keyword to prevent service disruption.

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2454369Suricata: Suricata: Denial of Service via 'tls.alpn' rule keyword

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.

CVSS3: 7.5
nvd
4 месяца назад

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.

CVSS3: 7.5
debian
4 месяца назад

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to b ...

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость системы обнаружения и предотвращения вторжений Suricata, связанная с разыменованием указателей, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3