important · Network sensor
Traffic crossing Suricata can corrupt the sensor through two unauthenticated HTTP/2 memory-safety failures.
Affects
Suricata, the open-source IDS/IPS and network-security-monitoring engine commonly deployed inline or passively on Linux.
One path uses DoH2 state confusion to produce an invalid free; the other leaves HTTP/2 inspection holding storage that selected response-header rules have freed or reallocated.
Detail and 5 sources
OISF patched both failures.
Chain to watch
Send a flow through the inspected path→↓Trigger invalid-free or use-after-free conditions→↓Corrupt the Suricata inspection process→↓Deterministic process takeover remains unproven.
Unverified chainReplay both trigger classes against ASAN and packaged binaries, then measure reliability, allocator control and process containment.
No held source demonstrates reliable crashing, allocation control or code execution.
Sources
ResearchSuricata 8.0.7 released! - SuricataPatchdoh2: handle http1->http2->doh2 upgrade in one packet · OISF/suricata@e574009 · GitHubPatchhttp2/detect: avoids use-after-free with Http2ThreadMultiBuf · OISF/suricata@1d66355 · GitHubSecondaryCVE-2026-94083: network-triggered type confusion and invalid free in Suricata DoH2 inspectionSecondaryCVE-2026-94084: rule-dependent HTTP/2 use-after-free in Suricata