VDB

DEBIAN-CVE-2024-37151

DEBIAN-CVE-2024-37151 PUBLISHED CVSS 7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:11suricata0, 0, 6.0.1-3
Debian:14suricata0, 0
Debian:13suricata0, 0
Debian:12suricata1:7.0.10-1, 1:7.0.10-1~bpo12+1, 1:7.0.2-1

Timeline

  • Jul 11, 2024 CVE Published
  • May 16, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›