← Vulnerability feed

Vulnerability record · CVE-2019-15699 · published 24 September 2019

CVE-2019-15699: Suricata-ids suricata out-of-bounds read vulnerability

SSuricata Ids · Suricata

An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.

9.1 CVSS 3.1 Critical EPSS 1.6% · top 24.3% CWE-125 · Out-of-bounds read
9.1CVSS 3.1 base score, v2 6.4
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15699 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16411Suricata-ids suricata out-of-bounds read vulnerabilityAn issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in d…EPSS 2.0%9.8CVE-2019-10053Suricata-ids suricata out-of-bounds read vulnerabilityAn issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the prog…EPSS 1.7%9.1CVE-2019-16410Suricata-ids suricata out-of-bounds read vulnerabilityAn issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a …EPSS 2.1%7.5CVE-2019-10054Suricata-ids suricata improper input validation vulnerabilityAn issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memo…EPSS 1.4%7.5CVE-2019-10055Suricata-ids suricata integer overflow vulnerabilityAn issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within …EPSS 1.5%7.5CVE-2019-10056Suricata-ids suricata out-of-bounds write vulnerabilityAn issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type, such that the function Decod…EPSS 1.4%7.5CVE-2019-10052Suricata-ids suricata vulnerabilityAn issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to access a part of a DHCP packet. …EPSS 2.1%7.5CVE-2019-10051Suricata-ids suricata vulnerabilityAn issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the …EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2019-15699), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.