The OISF (Open Information Security Foundation) has released corrective updates for the Suricata Intrusion Detection and Prevention System versions 6.0.3 and 5.0.7, which fix the vulnerability CVE-2021-35063, classified as critical. This issue allows the bypassing of all Suricata analyzers and checks.
The vulnerability is caused by the disabling of stream analysis for packets with a non-zero ACK value but with the ACK bit not set, which allowed initiating a TCP session with a SYN packet having a non-zero ACK, effectively taking the entire TCP connection out of Suricata's inspection area. Such packets were recognized as erroneous in Suricata, and the handlers returned an error code without parsing the content.
Source: opennet.ru
