PT-2024-10010 · Suricata+2 · Suricata+2

Molenzwiebel

+2

·

Published

2024-12-12

·

Updated

2025-11-07

·

CVE-2024-55629

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 7.0.8
Description The issue is related to Suricata's handling of TCP urgent data, which can lead to possible evasions due to differences in data analysis between Suricata and the applications at the TCP endpoints. This can potentially allow a remote attacker to impact the integrity of protected information. Suricata 7.0.8 includes options to configure how to handle TCP urgent data, mitigating the risk.
Recommendations For versions prior to 7.0.8, consider updating to Suricata 7.0.8 to mitigate the risk. In IPS mode, use a rule such as "drop tcp any any -> any any (sid:1; tcp.flags:U*;)" to drop all packets with the urgent flag set, as a temporary workaround until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14099
BDU:2025-00137
CVE-2024-55629
GHSA-69WR-VHWG-84H2
OPENSUSE-SU-2025:15394-1

Affected Products

Alt Linux
Debian
Suricata