Security #7067
closed
Ouch `tracker->ip_hdr_offset` 4 is greater than GET_PKT_LEN(r)
0
The pcap does trigger only on fuzz_decodepcapfile, not on suricata
Here is a pcap reproducer
I had to do mergecap -a -w lolc.pcap lolb.pcap lolb.pcap
because fuzzing runs the input twice (to check for leaks)
- Status changed from New to Assigned
- Status changed from Assigned to In Review
- Label Needs backport to 7.0 added
- Label deleted (
Needs backport to 7.0)
- Tracker changed from Bug to Security
- Severity set to MODERATE
- Disclosure Date set to 09/04/2024
- Assignee changed from Victor Julien to Philippe Antoine
- Severity changed from MODERATE to HIGH
HIGH as it could potentially lead to loss of visibility, and thus policy bypass.
- Subject changed from defrag: DEBUG_VALIDATE_BUG_ON(len > UINT16_MAX); to defrag: off by one leads to possible evasion
- Status changed from In Review to Closed
- Private changed from Yes to No
Also available in: Atom
PDF