CVE-2024-37151

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. 
Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
GitHub_MCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
oisfsuricata
6.0.0 ≤
𝑥
< 6.0.20
oisfsuricata
7.0.0 ≤
𝑥
< 7.0.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
suricata
bullseye
vulnerable
bookworm
no-dsa
bullseye (security)
1:6.0.1-3+deb11u1
fixed
trixie
1:7.0.10-1+deb13u1
fixed
forky
1:8.0.2-1
fixed
sid
1:8.0.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
suricata
questing
not-affected
plucky
not-affected
oracular
not-affected
noble
needs-triage
jammy
needs-triage
focal
dne
bionic
needs-triage
xenial
needs-triage