Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to very large DNS log records. While there are limits in place, they were too generous. The issue has been addressed in Suricata 7.0.8.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Mar 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Oisf
Oisf suricata |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* | |
Vendors & Products |
Oisf
Oisf suricata |
Mon, 06 Jan 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 06 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to very large DNS log records. While there are limits in place, they were too generous. The issue has been addressed in Suricata 7.0.8. | |
Title | Suricata oversized resource names utilizing DNS name compression can lead to resource starvation | |
Weaknesses | CWE-405 CWE-779 |
|
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-06T19:14:33.486Z
Reserved: 2024-12-09T17:48:05.557Z
Link: CVE-2024-55628

Updated: 2025-01-06T19:14:28.578Z

Status : Analyzed
Published: 2025-01-06T18:15:22.947
Modified: 2025-03-31T13:02:25.710
Link: CVE-2024-55628

No data.