Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead to a very large buffer overflow while being zero-filled during initialization with memset due to an unsigned integer underflow. The issue has been addressed in Suricata 7.0.8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-122",
"CWE-191"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55627.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.0.8"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55627.json"
[
{
"target": {
"function": "RegionsIntersect",
"file": "src/util-streaming-buffer.c"
},
"deprecated": false,
"source": "https://github.com/oisf/suricata/commit/282509f70c4ce805098e59535af445362e3e9ebd",
"id": "CVE-2024-55627-4df653df",
"signature_version": "v1",
"digest": {
"length": 866.0,
"function_hash": "259861547785025861481201231218251255449"
},
"signature_type": "Function"
},
{
"target": {
"file": "src/util-streaming-buffer.c"
},
"deprecated": false,
"source": "https://github.com/oisf/suricata/commit/9a53ec43b13f0039a083950511a18bf6f408e432",
"id": "CVE-2024-55627-5ae3252d",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"266125231482275613620453692551390974748",
"76876518019900599749506754822473078345",
"210621468521259345856339269593848310112",
"173951470108531132155823688866244144521"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "StreamingBufferSlideToOffsetWithRegions",
"file": "src/util-streaming-buffer.c"
},
"deprecated": false,
"source": "https://github.com/oisf/suricata/commit/8900041405dbb5f9584edae994af2100733fb4be",
"id": "CVE-2024-55627-a9b75f65",
"signature_version": "v1",
"digest": {
"length": 5288.0,
"function_hash": "238718882176217233228880165431272206481"
},
"signature_type": "Function"
},
{
"target": {
"function": "GrowRegionToSize",
"file": "src/util-streaming-buffer.c"
},
"deprecated": false,
"source": "https://github.com/oisf/suricata/commit/9a53ec43b13f0039a083950511a18bf6f408e432",
"id": "CVE-2024-55627-b97e3ee0",
"signature_version": "v1",
"digest": {
"length": 1026.0,
"function_hash": "232609525779236138347058802935225747383"
},
"signature_type": "Function"
},
{
"target": {
"file": "src/util-streaming-buffer.c"
},
"deprecated": false,
"source": "https://github.com/oisf/suricata/commit/8900041405dbb5f9584edae994af2100733fb4be",
"id": "CVE-2024-55627-e4699552",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"257557541687097623218234308184626516629",
"239240936764277671536039963550347713053",
"106555919402832637769410757283088245650",
"101822752348985804601538756308892156184",
"205231554738048531018152567405208937655",
"102077250039258144940778726403309526922"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "src/util-streaming-buffer.c"
},
"deprecated": false,
"source": "https://github.com/oisf/suricata/commit/282509f70c4ce805098e59535af445362e3e9ebd",
"id": "CVE-2024-55627-f37cc257",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"191152371183360166552815074705507997963",
"38520660100861342629012367909609220593",
"108549116729929080365552621141700791317",
"93137806532437528296664267105847564693",
"64572255665510981376589991839446389734",
"133542649055328559176821785520589268881",
"227562000857526438488888190134694099397",
"72885844214722670193232735668668273192",
"132895665556498937183610575312045164474",
"105332709102192219867573264649097063913",
"234439817126466643255133082764768516544",
"14038891257201561125378907730729851665",
"292275334834507353626725329587287327121",
"32533221277276569027191104455787419647"
]
},
"signature_type": "Line"
}
]
"2026-08-12T14:52:20Z"