PT-2026-95903 · Suricata · Suricata
CVE-2026-94084
·
Published
2026-09-20
·
Updated
2026-09-22
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Suricata versions prior to 8.0.7
Description
A use-after-free flaw exists in the
Http2ThreadMultiBuf component. This occurs when the system inspects HTTP/2 transactions using rules that apply http.response header both with and without a transform. A use-after-free is a memory corruption issue where the software continues to use a memory address after it has been freed. This can be triggered by unauthenticated attackers sending crafted HTTP/2 traffic, potentially leading to process crashes or arbitrary code execution.Recommendations
Update Suricata to version 8.0.7 or higher.
Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suricata