Impact
Suricata includes a Lua TLS certificate helper that can dereference a NULL pointer when a Lua script requests certificate information for TLS traffic that lacks some certificate fields. The vulnerable code will crash Suricata, causing a denial of service whenever crafted TLS traffic is processed by an affected deployment. The flaw is a null pointer dereference (CWE‑476).
Affected Systems
The issue affects the OISF Suricata engine versions prior to 7.0.16. Suricata installations that employ Lua TLS scripting, particularly those serving untrusted traffic, are impacted. Users should confirm that their Suricata version is 7.0.16 or newer to ensure the crash‑bypass patch is present.
Risk and Exploitability
The advisory indicates a CVSS score of 7.5, which represents medium‑to‑high severity. The attack vector is remote and requires the attacker to send specially crafted TLS traffic to the Suricata node, after which the system will crash and cease functioning. Because the vulnerability does not grant code execution or privilege escalation, but causes a denial of service, the overall risk is confined to availability loss. There is no listing in the CISA KEV catalog and EPSS information is not provided, so historical exploitation data is unavailable. Consequently, while the flaw is mitigable by updating Suricata, it remains a notable risk for environments that cannot upgrade immediately, especially those that expose Suricata to untrusted traffic.
OpenCVE Enrichment