Unrated severityNVD Advisory· Published Feb 26, 2024· Updated Feb 13, 2025
Suricata's pgsql: memory exhaustion use on record parsing
CVE-2024-23835
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround, users can disable the pgsql app layer parser.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/OISF/suricata/commit/86de7cffa7e8f06fe9d600127e7dabe89c7e81ddmitrex_refsource_MISC
- github.com/OISF/suricata/commit/f52c033e566beafb4480c139eb18662a2870464fmitrex_refsource_MISC
- github.com/OISF/suricata/security/advisories/GHSA-8583-353f-mvwcmitrex_refsource_CONFIRM
- redmine.openinfosecfoundation.org/issues/6411mitrex_refsource_MISC
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GOCOBFUTIFHOP2PZOH4ENRFXRBHIRKK4/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXJIT7R53ZXROO3I256RFUWTIW4ECK6P/mitre
News mentions
0No linked articles in our index yet.