CVE-2024-37151: medium-severity vulnerability in OISF suricata
Suricata defrag: IP ID reuse can lead to policy bypass
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Suricata fails to properly reassemble fragmented network packets that reuse the same IP ID, allowing malicious traffic to bypass security policies. This flaw lets attackers evade detection by fragmenting packets in a way the system cannot properly reconstruct.
The defragmentation engine in Suricata mishandles multiple fragmented IP packets sharing identical ID values, resulting in reassembly failure. This allows attackers to craft fragmented packets that evade policy checks, particularly in network monitoring scenarios. Mitigation requires upgrading to versions 7.0.6 or 6.0.20, or enabling defrag on af-packet interfaces.
In the same product, most dangerous first.