Back to Database
Status published
Medium
CVE-2024-24568
Suricata http2: header handling evasion
Vulnerability Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-24568
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/OISF/suricata/security/advisories/GHSA-gv29-5hqw-5h8c
- https://github.com/OISF/suricata/commit/478a2a38f54e2ae235f8486bff87d7d66b6307f0
- https://redmine.openinfosecfoundation.org/issues/6717
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GOCOBFUTIFHOP2PZOH4ENRFXRBHIRKK4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXJIT7R53ZXROO3I256RFUWTIW4ECK6P/
More from OISF
View All →CVE-2025-64344
Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer
High
7.5
CVE-2025-64335
Suricata is vulnerable to a null deref when used with base64_data
High
7.5
CVE-2025-64334
Suricata is vulnerable to unbounded memory growth for decompression
High
7.5
CVE-2025-64333
Suricata is vulnerable to a stack overflow from big content-type
High
7.5
CVE-2025-64332
Suricata is vulnerable to a stack overflow on larger compressed data
High
7.5
Affected Vendor
OISF
View all reports →Affected Software
suricata
Vulnerable Versions:
>= 7.0.0, < 7.0.3
Timeline
Official Publish:
February 26th, 2024
Last Modified:
February 13th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N