Impact
A crafted Adobe Flash file can trigger an integer-related heap buffer overflow in Suricata’s HTTP SWF decompression routine when the non‑default swf‑decompression feature is enabled and an unsafe decompress‑depth is used. The vulnerability allows a malicious response to cause Suricata to allocate an insufficient buffer on the heap, resulting in a crash. This flaw is a classic Heap Buffer Overflow (CWE‑122) combined with an Integer Overflow (CWE‑190) that leads to loss of service rather than arbitrary code execution.
Affected Systems
The issue affects the Suricata network intrusion detection and prevention engine developed by the Open Information Security Foundation. Versions earlier than 7.0.17 and 8.0.6 that have the swf‑decompression feature enabled and an unsafe depth setting are vulnerable. All other versions, including those with the feature disabled or the default depth, are not impacted.
Risk and Exploitability
Suricata receives a CVSS score of 3.7, indicating low severity. Exploit probability data (EPSS) is not available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker can remotely deliver a malicious SWF document to Suricata over HTTP; when the vulnerable de‑compression logic processes the file, the service will crash, disrupting network monitoring. The attack requires the feature to be enabled and a non‑default depth, which are not set by default, reducing the attack surface but still allowing exploitation from a remote source.
OpenCVE Enrichment