Project

General

Profile

Actions

Bug #7725

open

decode/ipv4: missing ip-in-ip case handling

Added by Juliana Fajardini Reichow about 1 month ago. Updated 25 days ago.

Status:
Resolved
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

A flow with IPv4 IP in IP traffic won't handle this tunneling case properly.
This leads to potential malicious traffic not triggering alerts, as well as other
inaccuracies in the logs.

Check if this case is also missing in other scenarios.

Waiting to see if the pcap shared can be added to a public SV test.


Subtasks 1 (1 open0 closed)

Bug #7726: decode/ipv4: missing ip-in-ip case handling (7.0.x backport)In ReviewJuliana Fajardini ReichowActions

Related issues 2 (2 open0 closed)

Related to Suricata - Bug #4571: Unable to trigger rule by content in case of IPv4 in IPv4 incapsulationAssignedVictor JulienActions
Related to Suricata - Task #7734: decode: review if any decoders are missing for IPv4 or IPv6NewOISF DevActions
Actions #1

Updated by OISF Ticketbot about 1 month ago

  • Subtask #7726 added
Actions #2

Updated by OISF Ticketbot about 1 month ago

  • Label deleted (Needs backport to 7.0)
Actions #3

Updated by Juliana Fajardini Reichow about 1 month ago

  • Description updated (diff)
Actions #4

Updated by Juliana Fajardini Reichow about 1 month ago

Attempt at a fix shared on GL.

Actions #5

Updated by Juliana Fajardini Reichow about 1 month ago

  • Status changed from New to In Progress
  • Assignee changed from OISF Dev to Juliana Fajardini Reichow
Actions #6

Updated by Juliana Fajardini Reichow about 1 month ago

  • Status changed from In Progress to In Review
Actions #7

Updated by Juliana Fajardini Reichow 26 days ago

  • Private changed from Yes to No
Actions #8

Updated by Philippe Antoine 26 days ago

  • Related to Bug #4571: Unable to trigger rule by content in case of IPv4 in IPv4 incapsulation added
Actions #9

Updated by Philippe Antoine 25 days ago

  • Status changed from In Review to Resolved
Actions #10

Updated by Juliana Fajardini Reichow 19 days ago

  • Related to Task #7734: decode: review if any decoders are missing for IPv4 or IPv6 added
Actions

Also available in: Atom PDF