CVE-2026-31931
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the 'tls.alpn' rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.
476
NULL Pointer Dereference
StableCommon Consequences
Security Scopes Affected:
Availability
Integrity
Confidentiality
Potential Impacts:
Dos: Crash, Exit, Or Restart
Execute Unauthorized Code Or Commands
Read Memory
Modify Memory
Applicable Platforms
Languages:
C, C#, C++, Go, Java
https://github.com/OISF/suricata/security/advisories/GHSA-gr22-4784-xvw3
https://redmine.openinfosecfoundation.org/issues/8294