Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the Suricata network security technology could allow an attacker to cause disruptions if a specific protocol handling error occurs with DNS over HTTPS (DoH2) requests. While the technology is designed to monitor network traffic, the impact of this issue depends on how Suricata is configured and deployed within your environment. The primary concern is to confirm whether this specific functionality is enabled and if your deployment is exposed.
- Type confusion impacts network traffic analysis.
- Matters if the DoH2 feature is active.
- Confirm Suricata DoH2 relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker could trigger this vulnerability by sending a specially crafted DoH2 request that attempts to upgrade from HTTP1 to HTTP2. This specific request manipulates the software's internal handling of connection types, leading to a critical error. When this error occurs, the software attempts to clean up resources incorrectly, potentially allowing an attacker to gain significant control over the affected system.
- No special access needed.
- DoH2 request with HTTP1 to HTTP2 upgrade.
- Leads to code execution.
Live Threat
Current exploitation, exposure, and threat context
A type confusion in Suricata's DoH2 handling could lead to incorrect memory management when processing a specific sequence of HTTP requests, potentially affecting the integrity and availability of the Suricata service when app-layer DoH2 is enabled.
- Network traffic inspection.
- Malformed DoH2 requests with HTTP1 upgrade.
- Service instability or crashes.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Suricata product owner and the infrastructure team are likely responsible for addressing this vulnerability. The first practical step is to identify all deployed instances of Suricata, determine if the DoH2 feature is enabled, and assess their network exposure and criticality to prioritize remediation efforts.
- Suricata product owner, infrastructure team.
- Verify DoH2 feature, network exposure.
- Plan remediation based on risk.