Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3. https://github.com/OISF/suricata/commit/478a2a38f54e2ae235f8486bff87d7d66b6307f0 https://github.com/OISF/suricata/security/advisories/GHSA-gv29-5hqw-5h8c https://redmine.openinfosecfoundation.org/issues/6717
Created suricata tracking bugs for this issue: Affects: epel-all [bug 2266171] Affects: fedora-all [bug 2266172]