CVE-2024-37151

Source
https://cve.org/CVERecord?id=CVE-2024-37151
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-37151.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-37151
Aliases
  • GHSA-qrp7-g66m-px24
Downstream
Related
Published
2024-07-11T14:39:32.766Z
Modified
2026-05-15T04:08:21.578669797Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Suricata defrag: IP ID reuse can lead to policy bypass
Details

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable defrag to reduce the scope of the problem.

Database specific
{
    "cwe_ids": [
        "CWE-754"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37151.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages