Impact
Crafted traffic sending multiple SYN packets with different sequence numbers within the same flow tuple can cause Suricata to not pickup the TCP session.
In IDS mode this can lead to a detection and logging bypass.
In IPS mode this will lead to the flow getting blocked.
Patches
Upgrade to 7.0.12 or 8.0.1.
Workarounds
None
References
https://redmine.openinfosecfoundation.org/issues/7657
Impact
Crafted traffic sending multiple SYN packets with different sequence numbers within the same flow tuple can cause Suricata to not pickup the TCP session.
In IDS mode this can lead to a detection and logging bypass.
In IPS mode this will lead to the flow getting blocked.
Patches
Upgrade to 7.0.12 or 8.0.1.
Workarounds
None
References
https://redmine.openinfosecfoundation.org/issues/7657