Skip to finding
important · Network sensor

Traffic crossing Suricata can corrupt the sensor through two unauthenticated HTTP/2 memory-safety failures.

Affects

Suricata, the open-source IDS/IPS and network-security-monitoring engine commonly deployed inline or passively on Linux.

One path uses DoH2 state confusion to produce an invalid free; the other leaves HTTP/2 inspection holding storage that selected response-header rules have freed or reallocated.

Detail and 5 sources

OISF patched both failures.

Chain to watch
Send a flow through the inspected path→↓Trigger invalid-free or use-after-free conditions→↓Corrupt the Suricata inspection process→↓Deterministic process takeover remains unproven.
Unverified chainReplay both trigger classes against ASAN and packaged binaries, then measure reliability, allocator control and process containment.

No held source demonstrates reliable crashing, allocation control or code execution.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026