rootpwn

critical · CVSS v3 9.4

CVE-2026-94084

Suricata IDS/IPS versions prior to 8.0.7 are vulnerable to a use‑after‑free in the Http2ThreadMultiBuf component when rules inspect http.res

Overview

Suricata IDS/IPS versions prior to 8.0.7 are vulnerable to a use‑after‑free in the Http2ThreadMultiBuf component when rules inspect http.response_header, potentially causing a crash or memory corruption. This flaw can disrupt IDS operation and may allow attackers to force a denial of service. The issue is critical with a CVSS v3 score of 9.4.

Description

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

Impact

The vulnerability primarily impacts availability by allowing attackers to crash Suricata, leading to loss of network visibility. It could also enable memory corruption that might be leveraged for arbitrary code execution, threatening the integrity of the IDS system. Defenders using Suricata for perimeter or internal traffic monitoring are directly affected.

Remediation

Upgrade Suricata to version 8.0.7 or later, which contains the fix for the Http2ThreadMultiBuf use‑after‑free. If an upgrade is not immediately possible, disable http.response_header rules or temporarily turn off HTTP/2 inspection to mitigate the risk. Monitor system logs for unexpected crashes or memory errors.

Risk context

The CVE is rated critical with a CVSS v3 score of 9.4, indicating a high severity and urgent need for remediation. No EPSS data is available, but the critical rating warrants immediate action.

Affected products

  • Suricata 7.x
  • Suricata 8.0.0-8.0.6

Scores

Severity
critical
CVSS v2
9.7
CVSS v3
9.4
CVSS v4
EPSS

Suricata HTTP/2 use-after-free critical IDS denial-of-service patch

← All CVEs