Actions
Bug #4477
closedInfinite loops in when using InspectionBufferMultipleForList
Affected Versions:
Effort:
Difficulty:
Label:
Description
From https://github.com/OISF/suricata/pull/5622#discussion_r626686822
POC is in #4476 once the buffer overflow gets fixed
Root cause is integer loss of precision casting local_id
to uint16_t when there can more than 65536 buffers in a transaction
This may be not the case for dns.query
as the maximum PDU length is 65536
But this is definitely the case for MQTT (subscribe topics) where Suricata default maximum PDU is 1Mbyte
Actions