Project

General

Profile

Actions

Bug #8962

closed
SD SD

erf/file: ERF PAD and META type records and extension headers are not supported

Bug #8962: erf/file: ERF PAD and META type records and extension headers are not supported

Added by Stephen Donnelly 22 days ago. Updated 11 days ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The ERF format defines PAD and META type records which may exist in packet trace files and can/should be skipped by Suricata. The presence of these record types currently stops Suricata reading the input file.

The ERF format defines extension headers. The presence of ERF extension headers prevents Suricata from reading the input file.

Both of these ERF features are supported by source-erf-dag for live capture but not source-erf-file for file input.


Subtasks 1 (0 open1 closed)

Bug #9017: erf/file: ERF PAD and META type records and extension headers are not supported (8.0.x backport)ClosedStephen DonnellyActions

SD Updated by Stephen Donnelly 21 days ago Actions #1

  • Status changed from Assigned to In Review

SD Updated by Stephen Donnelly 19 days ago Actions #2

  • Status changed from In Review to Resolved

Merged to main in https://github.com/OISF/suricata/pull/16141

Victor does this need back-port to main-8.0.x ?

SD Updated by Stephen Donnelly 11 days ago Actions #3

  • Label Needs backport to 8.0 added

OT Updated by OISF Ticketbot 11 days ago Actions #4

  • Subtask #9017 added

OT Updated by OISF Ticketbot 11 days ago Actions #5

  • Label deleted (Needs backport to 8.0)

PA Updated by Philippe Antoine 11 days ago Actions #6

  • Status changed from Resolved to Closed
Actions

Also available in: PDF Atom