Suricata · Suricata · CVE-2024-47187
**Name of the Vulnerable Software and Affected Versions**
Suricata versions prior to 7.0.7
**Description**
Suricata is a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine. The issue arises from the missing initialization of the random seed for `thash`, leading to datasets having predictable hash table behavior. This results in dataset file loading taking excessive time and runtime performance issues during traffic handling.
**Recommendations**
For versions prior to 7.0.7, update to version 7.0.7 to address the issue.
As a temporary workaround, avoid loading datasets from untrusted sources.
Avoid using dataset rules that track traffic in rules to minimize the risk of exploitation.