Skip to content

Snort

v3.10.2.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Summary

AI summary

Appid adds configurable midstream service discovery, QUIC client preference, and fixes two out‑of‑bounds reads; control refactors connection ownership for better thread safety; extractor stops reporting default SSL field values when missing.

Full changelog

Dependencies:

  • Libdaq v3.0.24
  • LibML v2.0.0

Changes in this release since 3.10.1.0:

  • appid: configurable midstream service discovery
  • appid: prefer QUIC client appid over SSL
  • appid: prevent out-of-bounds read in bootp option parsing
  • appid: prevent out-of-bounds read in sslv2 server-hello detection
  • control: refactor connection ownership model and improve thread safety
  • extractor: avoid reporting default values for missing SSL fields
  • file_api: coverity fix
  • flow: refactor dump_flows command to dump flow state in binary format
  • mime: fix compile issues
  • react: block flow when packets are not reset candidates
  • show_flows: implement utility program to convert dump_flows binary files to text Flow state data for each flow
  • smtp: handle split CRLF in multi-line response parsing
  • ssl: ssl client hello event is published with empty hostname

Security Fixes

  • Appid: prevent out‑of‑bounds read in bootp option parsing
  • Appid: prevent out‑of‑bounds read in SSLv2 server‑hello detection

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Snort

Get notified when new releases ship.

Sign up free

About Snort

A network intrusion detection tool

All releases →

Related context

Beta — feedback welcome: [email protected]