CVE-2026-94084

9.4

OISF · Suricata

Suricata versions prior to 8.0.7 are vulnerable to a use-after-free condition in the Http2ThreadMultiBuf component during specific HTTP response header inspection scenarios.

Executive summary

An unauthenticated remote attacker can trigger a use-after-free vulnerability in OISF Suricata, potentially leading to arbitrary code execution or service disruption.

Vulnerability

This is a use-after-free vulnerability (CWE-416) occurring within the Http2ThreadMultiBuf component. The flaw is triggered when the inspection engine processes transactions using specific http.response_header rules, allowing an unauthenticated attacker to manipulate memory states.

Business impact

The high CVSS score of 9.4 reflects the critical nature of this flaw, as it allows for unauthenticated remote exploitation. Successful exploitation could lead to full system compromise or significant denial-of-service, disrupting critical network monitoring and security infrastructure.

Remediation

Immediate Action: Upgrade OISF Suricata to version 8.0.7 or later as specified in the official vendor release notes.

Proactive Monitoring: Monitor system logs for unexpected crashes of the Suricata service and review network traffic for patterns that trigger complex HTTP/2 header inspection.

Compensating Controls: Implement network-level access controls to restrict access to the sensor management interfaces, although this does not mitigate the inspection-based exploitation vector itself.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical CVSS severity and the core role of Suricata in organizational security, this update should be applied during the next maintenance window. Administrators must prioritize patching all sensor instances to version 8.0.7 to eliminate the risk of remote memory corruption and potential code execution.

More OISF CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources