Project

General

Profile

Actions

Security #7450

closed

tracking: signature can allocate arbitrary amount of memory

Added by Philippe Antoine 8 months ago. Updated 5 days ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Label:
CVE:
Git IDs:
Severity:
HIGH
Disclosure Date:
12/09/2024

Description

cf usage of FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION in util-thash.c and detect-base64-decode.c


Subtasks 5 (0 open5 closed)

Security #7451: tracking: signature can allocate arbitrary amount of memory (7.0.x backport)ClosedPhilippe AntoineActions
Security #7613: decode_base64: signature can do large memory allocationClosedPhilippe AntoineActions
Security #7614: decode_base64: signature can do large memory allocation (7.0.x backport)ClosedPhilippe AntoineActions
Security #7615: datasets: signature keyword setting can cause high memory usageClosedPhilippe AntoineActions
Security #7616: datasets: hashsize setting via rules can cause high memory usage (7.0.x backport)ClosedPhilippe AntoineActions

Related issues 2 (0 open2 closed)

Related to Suricata - Task #7461: suricata-verify: pass all testsClosedPhilippe AntoineActions
Related to Suricata - Bug #7462: suricata-verify: pass when compiled with FUZZING_UNSAFERejectedPhilippe AntoineActions
Actions #1

Updated by OISF Ticketbot 8 months ago

  • Subtask #7451 added
Actions #2

Updated by OISF Ticketbot 8 months ago

  • Label deleted (Needs backport to 7.0)
Actions #3

Updated by Philippe Antoine 7 months ago

  • Blocked by Task #7461: suricata-verify: pass all tests added
Actions #4

Updated by Philippe Antoine 7 months ago

  • Blocked by deleted (Task #7461: suricata-verify: pass all tests)
Actions #5

Updated by Philippe Antoine 7 months ago

  • Related to Task #7461: suricata-verify: pass all tests added
Actions #6

Updated by Philippe Antoine 7 months ago

  • Related to Bug #7462: suricata-verify: pass when compiled with FUZZING_UNSAFE added
Actions #7

Updated by Philippe Antoine 7 months ago

  • Status changed from New to In Review

Some POC in Gitlab to discuss on

Actions #8

Updated by Victor Julien 4 months ago

  • Subtask #7613 added
Actions #9

Updated by Victor Julien 4 months ago

  • Subtask #7615 added
Actions #10

Updated by Victor Julien 4 months ago

Need to keep this private until all known vectors are fixed and part of a public release.

Actions #11

Updated by Victor Julien 4 months ago

  • Subject changed from signature can allocate arbitrary amount of memory to tracking: signature can allocate arbitrary amount of memory
  • Status changed from In Review to In Progress
  • Assignee changed from Philippe Antoine to Victor Julien
Actions #12

Updated by Jason Ish 4 months ago

  • Severity changed from MODERATE to HIGH
Actions #13

Updated by Philippe Antoine 4 months ago

  • Status changed from In Progress to Closed
Actions #14

Updated by Jason Ish 5 days ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF