JI Jason Ish
- Login: jish
- Email: jish@oisf.net, jason.ish@gmail.com
- Registered on: 11/09/2009
- Last sign in: 10/01/2026
Issues
| open | closed | Total | |
|---|---|---|---|
| Assigned issues | 77 | 747 | 824 |
| Reported issues | 137 | 460 | 597 |
Projects
| Project | Roles | Registered on |
|---|---|---|
| Suricata | Developer, OISF Team, OISF Manager | 11/09/2009 |
| Suricata-Update | Developer, OISF Team, OISF Manager | 10/31/2017 |
Activity
10/01/2026
- JI 10:02 PM Suricata Feature #9150 (New): libsuricata: support stream input without synthetic packets
- Library users should be able to feed already-reassembled application data into Suricata without constructing synthetic TCP/IP packets or emulating TCP state.
This is useful for proxies, ICAP services, and other applications that alrea...
09/29/2026
- JI 02:49 PM Suricata Bug #9122 (Resolved): firewall: file.data auto-prior-accept bypass
09/25/2026
- JI 11:41 PM Suricata Bug #9138 (In Review): detect/analyzer: Empty rules_fast_pattern.txt (8.0.x backport)
- PR: https://github.com/OISF/suricata/pull/16310
- JI 11:21 PM Suricata Bug #9007 (Resolved): detect/analyzer: Empty rules_fast_pattern.txt
- Merged via https://github.com/OISF/suricata/pull/16219.
8.0 is affected and should be a simple backport. - JI 11:18 PM Suricata Bug #8232 (Closed): Underflow in DefragInsertFrag in defrag.c
- Merged via https://github.com/OISF/suricata/pull/16253.
- JI 10:19 PM Suricata Bug #9122 (In Review): firewall: file.data auto-prior-accept bypass
09/24/2026
- JI 10:01 PM Suricata Bug #9126: detect: byte_extract/byte_math values silently miscomputed via unchecked 64-to-32-bit truncation, enabling signature evasion
- Suricata-Verify pull request: https://github.com/OISF/suricata-verify/pull/3390
09/23/2026
- JI 11:33 PM Suricata Bug #9126 (New): detect: byte_extract/byte_math values silently miscomputed via unchecked 64-to-32-bit truncation, enabling signature evasion
- h2. DISCLOSURE UP FRONT
I want to be transparent before describing the issue. The truncation behavior itself is already documented in your source tree. The file src/detect-engine-content-inspection.c contains the developer comment "Th... - JI 11:18 PM Suricata Security #9125: vlan: PacketReinit() leaves vlan_id[2] stale on packet-pool recycle, splitting flows and enabling multi-segment rule evasion
- Possible impact: An attacker able to inject a triple-VLAN-tagged frame on a monitored segment may cause subsequent untagged packets to be assigned to a different flow. This can prevent Suricata from matching signatures that span TCP segm...
- JI 11:12 PM Suricata Security #9125 (In Review): vlan: PacketReinit() leaves vlan_id[2] stale on packet-pool recycle, splitting flows and enabling multi-segment rule evasion
- Reported as ANT-2026-TN5YYMMT.
We would like to report a detection-evasion issue in the packet-pool recycle path that
is present in the shipped default configuration of current main and the 7.0.x / 8.0.x
release branches. A self-con...