#VU128041 NULL pointer dereference in Suricata - CVE-2024-38536
Published: July 11, 2024 / Updated: April 27, 2026
Suricata
Open Information Security Foundation
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the http/range handling code when processing HTTP traffic after http.memcap is reached. A remote attacker can send network traffic that triggers memory allocation failure to cause a denial of service.