CVE-2024-23835 - CVE House
Back to Database
Status published High CVE-2024-23835

Suricata's pgsql: memory exhaustion use on record parsing

Vulnerability Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround, users can disable the pgsql app layer parser.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-23835

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

suricata
Vulnerable Versions:
>= 7.0.0, <= 7.0.2

Timeline

Official Publish: February 26th, 2024
Last Modified: February 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)