This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 10mo
SIEM & Threat Detection
✓ No known CVEs patched
This release patches 3 known CVEs
Affected surfaces
deps
rce_ssrf
Summary
AI summaryAppID fixes first-packet API, MDNS issues, TLS metadata handling; HTTP_Inspect adds partial header inspection and OPPORTUNISTIC_TLS publishing; Codecs override CISCO metadata default encoding.
Full changelog
Dependencies:
- Libdaq v3.0.21
- LibML v2.0.0
Changes in this release since 3.9.3.0 (3.9.4.0 was an internal tracking tag. No new commits between 3.9.3.0 and 3.9.4.0):
- appid: first packet API fixes for using asd instead of odp
- appid: fix multiple mdns issues
- appid: move tls metadata handling into single place
- codecs: override default encode for ciscometadata codec
- control: fix heap-use-after-free in is_local
- decompress: add unit test for vba decompression - infinite loops, divide-by-zero, integer overflow and out-of-bound
- file_api: clear file meta group before setting it during reload
- flow: clear flow ref in pkt on stale flow cleanup
- helpers: add syscall to flush new data written by SigSafePrinter to disk
- http_inspect: partial inspection for headers
- http_inspect: publish OPPORTUNISTIC_TLS
- imap: abort fallback functionality
- mp_dbus: make MPDataBusModule stats thread safe
- protocols: add sanity checks for tcp and ipv4 options to prevent out-of-buffer access
- ssl: fix unit test for OpenSSL v3+
- watchdog: replace watchdog command with atomic kicking from packet threads
Security Fixes
- control: fix heap-use-after-free in is_local
- decompress: add unit tests preventing infinite loops, divide-by-zero, integer overflow, out-of-bound errors
- protocols: add sanity checks for TCP and IPv4 options to prevent out-of-buffer access
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]