Impact
The vulnerability resides in Suricata's HTTP/2 decompression component, where a crafted HTTP/2 DATA frame with a high compression ratio can force the engine to allocate an unbounded buffer while decompressing gzip, deflate, or brotli data. This lack of a size bound may lead to excessive memory consumption or a crash, thereby denying service to the Suricata instance and the network it protects.
Affected Systems
The flaw affects all releases of the Open Information Security Foundation's Suricata IDS/IPS prior to version 7.0.16 and 8.0.5. Users running older firmware are vulnerable; the fix is incorporated in the 7.0.16 and 8.0.5 releases and onward.
Risk and Exploitability
The CVSS score of 7.5 denotes high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based attacker sending malicious HTTP/2 traffic; no special conditions beyond the presence of Suricata on the host are required. The absence of a memory limit makes the exploit straightforward, and the potential for a denial of service or crash on a critical network monitoring appliance places this risk in the moderate to high category if unmitigated.
OpenCVE Enrichment