Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.
Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.
Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4103-1 | suricata security update |
EUVD |
EUVD-2024-36467 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:oisf:suricata:6.0.0:-:*:*:*:*:*:* cpe:2.3:a:oisf:suricata:7.0.0:*:*:*:*:*:*:* |
|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T19:30:13.398Z
Reserved: 2024-06-03T17:29:38.328Z
Link: CVE-2024-37151
Updated: 2025-11-03T19:30:13.398Z
Status : Modified
Published: 2024-07-11T15:15:11.847
Modified: 2025-11-03T20:16:19.637
Link: CVE-2024-37151
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD