Suricata · Suricata · CVE-2024-23839
**Name of the Vulnerable Software and Affected Versions**
Suricata versions prior to 7.0.3
**Description**
The issue is related to a heap use after free condition that can be triggered by specially crafted traffic when the ruleset uses the `http.request header` or `http.response header` keyword. This can potentially allow a remote attacker to impact the integrity and availability of protected information.
**Recommendations**
To resolve the issue, update to version 7.0.3 or later.
As a temporary workaround, consider avoiding the use of the `http.request header` and `http.response header` keywords in the ruleset until a patch is applied.