Unrated severityNVD Advisory· Published Jul 11, 2024· Updated Aug 2, 2024
Suricata modbus: txs without responses are never freed
CVE-2024-38534
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within a flow. Upgrade to 7.0.6. Set a limited stream.reassembly.depth to reduce the issue.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/OISF/suricata/commit/a753cdbe84caee3b66d0bf49b2712d29a50d67aemitrex_refsource_MISC
- github.com/OISF/suricata/security/advisories/GHSA-59qg-h357-69fqmitrex_refsource_CONFIRM
- redmine.openinfosecfoundation.org/issues/6987mitrex_refsource_MISC
- redmine.openinfosecfoundation.org/issues/6988mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.