Suricata 是一个网络入侵检测系统(IDS)、入侵防御系统(IPS)和网络安全监控引擎。在 7.0.16 和 8.0.5 版本之前,在处理 HTTP/2 流量时发生的协议变更可能导致 Suricata 中出现类型混淆(type confusion)问题。经过精心构造的流量可能引发 Suricata 崩溃,从而导致服务拒绝(DoS)漏洞。7.0.16 和 8.0.5 版本已包含修复。作为临时缓解措施,如果不需要 HTTP/2 解析,可以将其禁用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45747 | 7.5 HIGH | Suricata lua/tls: null dereference in TlsGetCertInfo |
| CVE-2026-46387 | 7.5 HIGH | Suricata http2: decompression bomb can cause denial of service in Suricata |
| CVE-2026-45759 | 7.5 HIGH | Suricata http1: quadratic Content-Disposition processing can lead to denial of service |
| CVE-2026-45762 | 7.5 HIGH | Suricata defrag: missing address-family check can lead to remote crash |
| CVE-2026-45763 | 5.9 MEDIUM | Suricata lua: sandbox allocation limit not enforced for new allocations |
| CVE-2026-45751 | 5.9 MEDIUM | Suricata detect/transform: use-after-free in dotprefix transform |
| CVE-2026-45752 | 5.9 MEDIUM | Suricata detect/transform: use-after-free in decompress transforms |
| CVE-2026-45761 | 3.3 LOW | Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rul |
No comments yet