CVE-2026-94083
Description
A flaw was found in Suricata's DNS over HTTPS 2 (DoH2) application-layer protocol parser. When processing a DoH2 request accompanied by an HTTP/1 to HTTP/2 upgrade, Suricata mistakenly executes HTTP/2 state cleanup logic while the protocol handler is in an HTTP/1 state. A remote, unauthenticated attacker can exploit this type confusion by sending crafted protocol upgrade traffic to trigger an invalid memory free. This can result in a daemon crash leading to Denial of Service (DoS) or potentially arbitrary code execution within the privileges of the Suricata process. This issue affects Suricata versions prior to 8.0.7 when app-layer.protocols.doh2 is enabled.
Statement
A flaw was found in Suricata's DNS over HTTPS 2 (DoH2) application-layer protocol handler. When processing a DoH2 request accompanied by an HTTP/1 to HTTP/2 connection upgrade, Suricata incorrectly executes HTTP/2 state cleanup logic while in an HTTP/1 state. This type confusion triggers an invalid memory free, which a remote, unauthenticated attacker can exploit by sending crafted protocol upgrade traffic to crash the Suricata daemon or potentially execute arbitrary code with the privileges of the Suricata process.
Mitigation
Disable the DNS over HTTPS 2 protocol handler by setting `app-layer.protocols.doh2.enabled: false` in `/etc/suricata/suricata.yaml` and restart the Suricata service.
Understanding the Weakness (CWE)
Availability,Integrity,Confidentiality
Technical Impact: Read Memory; Modify Memory; Execute Unauthorized Code or Commands; DoS: Crash, Exit, or Restart
When a memory buffer is accessed using the wrong type, it could read or write memory out of the bounds of the buffer, if the allocated buffer is smaller than the type that the code is attempting to access, leading to a crash and possibly code execution.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.