PT-2024-10010 · Suricata+2 · Suricata+2
Molenzwiebel
+2
·
Published
2024-12-12
·
Updated
2025-11-07
·
CVE-2024-55629
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Suricata versions prior to 7.0.8
Description
The issue is related to Suricata's handling of TCP urgent data, which can lead to possible evasions due to differences in data analysis between Suricata and the applications at the TCP endpoints. This can potentially allow a remote attacker to impact the integrity of protected information. Suricata 7.0.8 includes options to configure how to handle TCP urgent data, mitigating the risk.
Recommendations
For versions prior to 7.0.8, consider updating to Suricata 7.0.8 to mitigate the risk.
In IPS mode, use a rule such as "drop tcp any any -> any any (sid:1; tcp.flags:U*;)" to drop all packets with the urgent flag set, as a temporary workaround until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Suricata