This is an extra release to address a critical issue in 7.0.9 affecting AF_PACKET users: setting a BPF would cause Suricata to fail to start up. This has been fixed. Various security, performance, accuracy, and stability issues have been fixed. LibHTP has been updated to version 0.5.50 which is bundled with this new. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2a295896e6 2025-04-03 01:51:21.151653+00:00 -------------------------------------------------------------------------------- Name : suricata Product : Fedora 40 Version : 7.0.10 Release : 1.fc40 URL : Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. -------------------------------------------------------------------------------- Update Information: This is an extra release to address a critical issue in 7.0.9 affecting AF_PACKET users: setting a BPF would cause Suricata to fail to start up. This has been fixed. Various security, performance, accuracy, and stability issues have been fixed. LibHTP has been updated to version 0.5.50 which is bundled with this new release. This fixes: CVE-2025-29915: HIGH CVE-2025-29917: HIGH CVE-2025-29918: HIGH CVE-2025-29916: Moderate -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 25 2025 Steve Grubb 7.0.10-1 - New bugfix release * Tue Mar 18 2025 Steve Grubb 7.0.9-1 - New security and bugfix release * Tue Feb 11 2025 Zbigniew JÄdrzejewski-Szmek - 7.0.8-3 - Add sysusers.d config file to allow rpm to create users/groupsautomatically * Sun Jan 19 2025 Fedora Release Engineering - 7.0.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2a295896e6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . Addresses significant vulnerabilities within Suricata impacting AF_PACKET functionality, introducing enhancements for both performance and stability in Fedora 40.. Intrusion Detection System, Fedora Updates, Network Security. . Severity: Critical. LinuxSecurity.com Team
Several issues have been found in suricata, the next Generation Intrusion Detection and Prevention Tool. They are related to bypass of HTTP-based signature, mishandling of multiple fragmented packets, logic errors, . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4103-1
Various security, performance, accuracy, and stability issues have been fixed.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-aa783e1cbd 2025-01-12 01:42:08.024032+00:00 -------------------------------------------------------------------------------- Name : suricata Product : Fedora 40 Version : 7.0.8 Release : 1.fc40 URL : / Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. -------------------------------------------------------------------------------- Update Information: Various security, performance, accuracy, and stability issues have been fixed. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 3 2025 Steve Grubb 7.0.8-1 - New security and bugfix release * Tue Oct 22 2024 Richard W.M. Jones - 7.0.7-2 - Rebuild for Jansson 2.14 (https://lists.fedoraproject.org/archives/list/
Various security, performance, accuracy, and stability issues have been fixed.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e24171db6d 2025-01-12 01:37:12.378708+00:00 -------------------------------------------------------------------------------- Name : suricata Product : Fedora 41 Version : 7.0.8 Release : 1.fc41 URL : / Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. -------------------------------------------------------------------------------- Update Information: Various security, performance, accuracy, and stability issues have been fixed. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 3 2025 Steve Grubb 7.0.8-1 - New security and bugfix release * Tue Oct 22 2024 Richard W.M. Jones - 7.0.7-2 - Rebuild for Jansson 2.14 (https://lists.fedoraproject.org/archives/list/
CVE-2024-37151 Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. CVE-2024-38534 Crafted modbus traffic can lead to unlimited resource accumulation within a flow . MGASA-2024-0306 - Updated suricata packages fix security vulnerabilities Publication date: 17 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0306.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-37151, CVE-2024-38534, CVE-2024-38535, CVE-2024-38536 CVE-2024-37151 Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. CVE-2024-38534 Crafted modbus traffic can lead to unlimited resource accumulation within a flow CVE-2024-38535, CVE-2024-38536 Suricata can run out of memory when parsing crafted HTTP/2 traffic. References: - https://bugs.mageia.org/show_bug.cgi?id=33431 - https://lists.fedoraproject.org/archives/list/
This is a security and bug fix release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-9cce1f4b49 2024-05-19 01:29:46.920838 -------------------------------------------------------------------------------- Name : suricata Product : Fedora 40 Version : 7.0.5 Release : 1.fc40 URL : / Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. -------------------------------------------------------------------------------- Update Information: This is a security and bug fix release. -------------------------------------------------------------------------------- ChangeLog: * Tue May 7 2024 Steve Grubb 7.0.5-1 - New security and bugfix release -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-9cce1f4b49' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
These are bug fix and security releases including MODERATE, HIGH, and CRITICAL issues.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-34eba1b1a6 2024-03-31 01:53:51.907834 -------------------------------------------------------------------------------- Name : suricata Product : Fedora 38 Version : 6.0.17 Release : 1.fc38 URL : Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. -------------------------------------------------------------------------------- Update Information: These are bug fix and security releases including MODERATE, HIGH, and CRITICAL issues. -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 20 2024 Steve Grubb 6.0.17-1 - New security and bugfix release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2128376 - Please port your pcre dependency to pcre2. Pcre has been deprecated https://bugzilla.redhat.com/show_bug.cgi?id=2128376 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-34eba1b1a6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
These are bug fix and security releases including MODERATE, HIGH, and CRITICAL issues.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-99337cc4a1 2024-03-31 01:12:46.078681 -------------------------------------------------------------------------------- Name : suricata Product : Fedora 39 Version : 6.0.17 Release : 1.fc39 URL : Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. -------------------------------------------------------------------------------- Update Information: These are bug fix and security releases including MODERATE, HIGH, and CRITICAL issues. -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 20 2024 Steve Grubb 6.0.17-1 - New security and bugfix release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2128376 - Please port your pcre dependency to pcre2. Pcre has been deprecated https://bugzilla.redhat.com/show_bug.cgi?id=2128376 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-99337cc4a1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.