CVE-2024-37151

Description

A flaw was found in suricata where a mishandling of multiple fragmented packets using the same IP ID value can lead to failure of the packet reassembly, possibly leading to a bypass of configured policies.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

When using af-packet, enable `defrag` to reduce the scope of the problem.

Understanding the Weakness (CWE)

Integrity,Availability

Technical Impact: DoS: Crash, Exit, or Restart; Unexpected State

The data which were produced as a result of a function call could be in a bad state upon return. If the return value is not checked, then this bad data may be used in operations, possibly leading to a crash or other unintended behaviors.

Frequently Asked Questions

Want to get errata notifications? Sign up here.