Impact
Suricata versions prior to 8.0.7 contain a use‑after‑free flaw in the Http2ThreadMultiBuf component that is triggered when a transaction is examined by rules using http.response_header, whether a transform is applied or not. The bug can cause memory corruption, resulting in a process crash or, depending on the execution context, execution of arbitrary code, which would compromise the integrity and availability of the network monitoring system. The weakness is classified as CWE‑416 and the CVSS score of 9.4 indicates a critical severity.
Affected Systems
Affected are all installations of Suricata from the OISF project that are running version 8.0.6 or earlier. No specific patch level or product sub‑variant is listed beyond the overall 8.0.6/8.0.7 distinction, so any deployment of Suricata 8.0.6 or older is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.4 reflects high exploit potential, but the EPSS score is currently not available, so precise likelihood of exploitation in the wild is unknown. The vulnerability is not yet listed in CISA’s KEV catalog. The most likely attack vector is a malicious HTTP/2 transaction crafted to trigger the rule engine, which is a remote attack if the Suricata instance is exposed to untrusted traffic. Because the flaw is triggered by rule matching, an attacker could construct a payload that forces the rule engine to parse a header that leads to the use‑after‑free, potentially including a malicious transform. Without a patch, the system is at imminent risk of compromise or denial of service.
OpenCVE Enrichment