Impact
Suricata 8.x contains a type confusion flaw in its DoH2 implementation that can trigger an invalid free when the cleanup code for HTTP/2 is executed while the state is actually HTTP/1. This bug manifests when an attacker sends a DoH2 request that includes an HTTP/1 to HTTP/2 upgrade sequence; the result is a heap corruption that can be leveraged for denial of service or arbitrary code execution. The flaw is an instance of unauthorized data deallocation (CWE‑843), escalating usage of memory to permit exploitation. The impact is focused on the Suricata instance processing the traffic, potentially exposing the host to destabilization or compromise.
Affected Systems
The vulnerability affects all OISF Suricata releases prior to version 8.0.7, which is the first release to contain the fix. All 8.x series installations that still run 8.0.6 or earlier are vulnerable. The vulnerability requires the configuration option app-layer.protocols.doh2 to be enabled, which is the default setting in the 8.x releases.
Risk and Exploitability
The CVSS score of 9.4 signals a critical severity, and although the EPSS score is not available, the lack of listing in the CISA KEV catalog does not diminish the potential for exploitation. The faulty code executes during normal network inspection of DoH traffic, so an attacker only needs to inject specially crafted traffic over the network to trigger the bug. Given that Suricata is commonly positioned as a network security sensor, the flaw poses a high risk to environments where it handles DoH connections.
OpenCVE Enrichment