Suricata 是一款集网络入侵检测系统、入侵防御系统和网络安全监控引擎于一体的安全工具。在 7.0.16 和 8.0.5 版本之前,Suricata 的 HTTP/2 解压缩处理路径中,解压缩后的响应体缓冲区可能在没有有效上限的情况下持续增长。攻击者可以利用精心构造的 HTTP/2 DATA 载荷(例如使用高压缩比的 gzip、deflate 或 brotli 压缩数据),导致 Suricata 在解压缩过程中分配过多的内存,从而引发内存耗尽问题。7.0.16 和 8.0.5 版本已修复此漏洞。作为临时应对措施
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45747 | 7.5 HIGH | Suricata lua/tls: null dereference in TlsGetCertInfo |
| CVE-2026-45763 | 5.9 MEDIUM | Suricata lua: sandbox allocation limit not enforced for new allocations |
No comments yet