suricata (1:6.0.1-3+deb11u1) bullseye-security; urgency=medium
authorThorsten Alteholz <debian@alteholz.de>
Sun, 30 Mar 2025 10:03:02 +0000 (12:03 +0200)
committerThorsten Alteholz <debian@alteholz.de>
Sun, 30 Mar 2025 10:03:02 +0000 (12:03 +0200)
commitdb0e32fa0da9b3b3e8deadb0eda671b7ea61549b
treeaaedb72419b3b784b904fea2e01ba186acee7408
parentdb5887e2ddd60c5a02173ac1ff1aff3447393708
parentf805f6659a602418434529268923b737d8a25b3e
suricata (1:6.0.1-3+deb11u1) bullseye-security; urgency=medium

  * Non-maintainer upload by the LTS Team.
  * CVE-2021-45098
    Fix bypass of HTTP-based signature by faking an RST TCP packet.
  * CVE-2023-35852
    Fix unintended file access in local filesystem.
  * CVE-2024-32663
    Fix using large amount of memory.
  * CVE-2024-37151
    Fix mishandling of multiple fragmented packets, which might lead to
    policy bypass.
  * CVE-2024-45796
    Fix logic error during fragment reassembly.
  * CVE-2025-29918
    Fix infinite loop.
  * CVE-2024-55626
    Fix buffer overflow due to large BPF filter file.

[dgit import unpatched suricata 1:6.0.1-3+deb11u1]
61 files changed:
debian/building-in-ci.sh
debian/changelog
debian/control
debian/copyright
debian/libhtp-0.5.24-1.install
debian/libhtp-0.5.24-1.lintian-overrides
debian/libhtp-0.5.24-1.symbols
debian/oinkmaster/suricata-oinkmaster
debian/oinkmaster/suricata-oinkmaster-updater
debian/oinkmaster/suricata-oinkmaster-updater.8
debian/oinkmaster/suricata-oinkmaster.conf
debian/patches/CVE-2021-45098.patch
debian/patches/CVE-2023-35852-1.patch
debian/patches/CVE-2023-35852-2.patch
debian/patches/CVE-2024-32663-1.patch
debian/patches/CVE-2024-32663-2.patch
debian/patches/CVE-2024-37151.patch
debian/patches/CVE-2024-45796.patch
debian/patches/CVE-2024-55626.patch
debian/patches/CVE-2025-29916-1.patch
debian/patches/CVE-2025-29916-2.patch
debian/patches/CVE-2025-29916-3.patch
debian/patches/CVE-2025-29917.patch
debian/patches/CVE-2025-29918.patch
debian/patches/avoid-to-include-if_tunnel-h.patch
debian/patches/configure-clang-variable.patch
debian/patches/cross.patch
debian/patches/debian-default-cfg.patch
debian/patches/fix-repeated-builds.patch
debian/patches/import-sockio-h.patch
debian/patches/llc.patch
debian/patches/no-use-gnu.patch
debian/patches/remove-conflicting-python-file.patch
debian/patches/reproducible.patch
debian/patches/series
debian/patches/stream-no-reject-bad-ack.patch
debian/patches/with-ebpf-includes.patch
debian/rules
debian/source/format
debian/suricata-oinkmaster.install
debian/suricata-oinkmaster.manpages
debian/suricata.1
debian/suricata.README.Debian
debian/suricata.default
debian/suricata.dirs
debian/suricata.init
debian/suricata.install
debian/suricata.lintian-overrides
debian/suricata.logrotate
debian/suricata.maintscript
debian/suricata.manpages
debian/suricata.preinst
debian/suricata.service
debian/suricatactl-filestore.1
debian/suricatactl.1
debian/suricatasc.1
debian/tests/control
debian/tests/suricata-oinkmaster-updater.sh
debian/tests/systemd-service-test.sh
debian/upstream/signing-key.asc
debian/watch