Impact
A large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup.
Patches
The issue has been addressed in Suricata 7.0.8.
Workarounds
Do not use untrusted files as an input to suricata -F
command line option.
References
https://redmine.openinfosecfoundation.org/issues/7366
Credits
Issue has been reported by Roman Ezhov (Positive Technologies).
Impact
A large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup.
Patches
The issue has been addressed in Suricata 7.0.8.
Workarounds
Do not use untrusted files as an input to
suricata -F
command line option.References
https://redmine.openinfosecfoundation.org/issues/7366
Credits
Issue has been reported by Roman Ezhov (Positive Technologies).