## OISF/suricata — suricata-8.0.6…suricata-8.0.7

_186+ commits._

### Features
- **lua/datasets: error on :add before :get** (9a8069c)
- **doc/configuration: add section about max-responses** (9015bd3)
- **etc/schema: explicitly add all MQTT properties** (b5b112f)
- **pgsql: add missing ErrorResponse fields to schema** (60c7ca5)
- **mqtt: add too_many_properties event and limit** (765a2dc)
- **ssl: add TOO_MANY_SUBJECT_ALTERNATIVE_NAMES event** (cd491b8)
- **defrag/ipv6: support maximum payload length** (e2d05ea)
- **detect: add tcp.session keyword for unified TCP lifecycle matching** (b800ace)
- **rfb/jsonschema: add missing field** (7ee6f32)
- **util/file: add unit test for inspect window overflow** (3b04b76)
- **firewall: add default-policy to policy config** (efc82a6)

### Fixes
- **detect/lua: fix per-thread mem limit disabling** (08cb90a)
- **pgsql: fix clippy warning** (f24d639)
- **nfs: fix allocation check in LAYOUTGET fh_handles** (537e6ef)
- **path: fix traversal check on Windows** (87afec2)
- **stream: tcp: fix AddAndRotate NULL deref with max-syn-queued 1** (7a862a6)
- **ftp/expectation: fix IPPair lock+refcount leak on alloc fail** (a8f1b5b)
- **stream-tcp: fix broken bitwise-NOT for 4WHS** (1e559cc)
- **schema: fix typos** (afdc483)
- **pgsql: fix regression in handling request gap** (b11da71)
- **detect: fix heap buffer overflow in DetectRunTx post-rule match** (d3eb4f9)
- **ssh: fix record_left for oversized KEXINIT records** (92859e3)
- **http1: fix gzip decompression with flags and multiple chunks** (4b79849)
- **dns: fix TCP request gap resync** (6a2b56e)
- **util: fix fallback memrchr() implementation** (8b0775f)
- **ssl: fix SSLv2 CLIENT_HELLO underflow** (d201942)
- **nfs: fix SECINFO_NO_NAME parser handling** (1bcfc21)
- **flow/rate: fix ring flushing** (53fd78a)
- **util/file: fix integer overflow in inspect window comparison** (c4b5f8d)
- **detect/threshold: fix unittests for storage based cache** (b72d0df)

### Backend
- **release: 8.0.7; update changelog** (d681600)
- **cppcheck: drop unreachable DEBUG_VALIDATE_BUG_ONs** (a00a26a)
- **smb: cap the OOO gap backstop by chunk count and inspect all open files** (f1c5715)
- **smb: rework the OOO file-data gap backstop to the queue limits** (4fa6970)
- **smb: enforce the write/read queue limits** (ca0d780)
- **nfs: bound the chunk-continuation stream skip by the record tail** (7ab8ba7)
- **nfs: rework and cap the OOO gap backstop to the queue limits** (1f407fd)
- **nfs: enforce the OOO queue limits on the chunk path** (26de470)
- **nfs: validate WRITE and READ records sizes** (cb2dee7)
- **nfs: enforce max read/write queue size and count limits** (0362baf)
- **rust: update ldap parser** (2d0af82)
- **lua/dataset: avoid uninitialized pointer use** (8d05511)
- **lua/datasets: validate string len** (17c4b60)
- **lua/flowvarlib: sanitize length in LuaFlowvarSet()** (b8fbe68)
- **ftp: a too-long line drops the rest of the stream slice** (923e039)
- **jsonschema: sort pgsql properties** (66abb81)
- **http2: strip padding bytes from PADDED HEADERS/PUSH_PROMISE frames** (6a44949)
- **http2: improve continuation frame reassembly** (0794dc6)
- **swf: validate configured depth limits** (c95ff7f)
- **swf: ignore FileLength when sizing output** (2be2256)
- **swf: grow lzma output in one decoder pass** (5ab8b5c)
- **swf: grow decompression buffer on demand** (eda28fa)
- **detect/threshold: bound the per-thread decision cache** (d827002)
- **sip: make pattern matching more robust** (2899262)
- **respond/reject: guard Ethernet setup against non-Ethernet packets** (5bbc237)
- **log/tcp-data: replace BUG_ON with graceful error handling** (e6fe867)
- **pcap/log: expand buffer before write in PcapLogSegmentCallback** (154dc10)
- **smb1: bound dialect count in NEGOTIATE_PROTOCOL parser** (2d47fb1)
- **threads: destroy pthread_attr_t before reuse** (a3a94d6)
- **dhcp: distinguish malformed and truncated options** (dad8363)
- **dhcp: validate address time option lengths** (5b882dd)
- **dhcp: parse pad option as single byte** (f5d47a8)
- **pgsql: bound tx.responses (configurable)** (c45d68e)
- **pgsql/logger: close json array if params truncated** (d38c2cc)
- **doc/eve-format: document row_description fields** (566861b)
- **pgsql: better boundaries to row_description/data_row** (dd53a71)
- **dnp3: preserve events when no current tx** (431a881)
- **dnp3: recover after link framing errors** (0f9deb9)
- **doh2: use right dns protocol to interpret tx** (321308f)
- **http: warn once for chunk extension** (a9594f8)
- **http: warn once for response 100-continue already seen** (9267edf)
- **http1: set all events in a flow** (a121a01)
- **http1: use strict brotli, forbid large window** (b3fca06)
- **http1: use brotli with owned BrotliState wrapper** (a005dbe)
- **http2: use strict brotli, forbid large window** (8c79af5)
- **http2: use brotli with owned BrotliState wrapper** (eac1c25)
- **ike: remove recursivity in functions** (ae2ebc2)
- **http2: respect max-table-size in headers size update** (b6e96e5)
- **http2: delay setting event during processing headers** (d0c8824)
- **http2: delay setting event during processing frame** (2c1eedb)
- **detect/bytetest: validate nbytes is non-negative** (9914e5e)
- **detect/bytejump: validate nbytes is positive** (f588030)
- **detect/engine: guard SCInspectionBufferCheckAndExpand against overflow** (fcf51f5)
- **detect/file: reset smd iterator for each file in multi-file txs** (180e0ae)
- **doh2: handle http1->http2->doh2 upgrade in one packet** (e574009)
- **rdp: treat tpkt payload as complete input** (33352db)
- **lua/hashlib: don't expose the hasher garbage collector** (c254d42)
- **mqtt: change the logging type of user properties** (e7cf632)
- **jsonbuilder: encode key strings when needed** (fccb490)
- **http2/detect: avoids use-after-free with Http2ThreadMultiBuf** (1d66355)
- **defrag: set nb_decoded_layers** (3e78c8d)
- **ldap: recover parsing after a gap** (257eef2)
- **ike: validate ISAKMP message length** (4614563)
- **ike: propagate version-specific parser result** (2d0f220)
- **pgsql: bound Copy responses to their length field** (9dfb981)
- **pgsql: use message type for transaction actions** (b0f703f)
- **flow/esp: use spi in hash** (0cdcacc)
- **mqtt: do not store unknown property** (db628ad)
- **x509: saturate SAN count returned by parser** (a36d8c1)
- **enip: make sure to have enough data for parser** (7d8612f)
- **smtp: handle file open failure** (78e4ff8)
- **ftp: mark truncation on the line, not the connection** (d0bba3b)
- **ftp: keep parsing after a truncated line's LF** (250eff9)
- **ftp: point truncated lines at the unconsumed remainder** (e58d4ed)
- **dnp3: allocate variable-length object fields dynamically** (27bb040)
- **dnp3-gen: update generated code to match clang-format** (ad33e1a)
- **lua: NULL-check update/finalize hasher functions** (e33f10c)
- **lua: validate signature argument to bytevar.map** (ae73d76)
- **lua: type-check userdata in flow, packet and dataset methods** (cbb0ac0)
- **defrag/ipv4: reject oversized reassembled packets** (7f0c329)
- **defrag/ipv6: reject oversized reassembled payloads** (b8ca9f2)
- **ftp: strip trailing whitespace before allocating** (bf68120)
- **doc/pcre: note that flow captures need a flow** (d727271)
- **detect/pcre: skip flow captures on flowless packets** (ebe8bd0)
- **lua/dns: handle OPT answers like TXT records** (c13440f)
- **enip: avoid quadratic complexity with multiple service packet** (3f59f26)
- **lua/smtp: avoid infinite loop for get_mime_list** (f46dc35)
- **detect: extend app-layer-protocol to accept a pipe-separated value list** (353885a)
- **output/alert: tolerate a reference with no key** (a2aa325)
- **detect/reference: set key on the unknown-key path** (f111a51)
- **smtp: recover from rejected BDAT commands** (27cb46c)
- **unix-socket: close socket and remove socket file on shutdown** (ec3a9aa)
- **rfb: keep failure_reason as Vec<u8>** (6c20427)
- **rfb: limit strings length** (51a6e69)
- **fw: document config action in FW mode** (4ca257b)
- **fw: disallow config to be used as a default policy** (6370f59)
- **fw: allow pass as a secondary action only for accept** (7b0fd81)
- **fw: validate scope inheritance in policies and rules** (610ecdb)
- **fw: respect configured policies in the rule analysis output** (e59df81)
- **logging: prevent double-free multi-threaded logging** (3d2171a)
- **source/erf: Handle ERF META and PAD record types and extension headers** (d5cb294)
- **erf/file: Don't trust ERF wlen and rlen from input file** (b5e22f7)
- **github-ci: remove Debian 11 build; Debian 11 is EOL** (c80c803)
- **tls: JA3 buffer pointers on allocation failure** (5f61a8a)
- **psl: update to 2.1.228** (0f3be94)
- **http2: log :authority header as hostname** (1969806)
- **http2: use host header for http.host keyword** (bae7033)
- **doc: update Rust installation instructions** (d8cd522)
- **http2: host normalization handles ipv6 address** (82c4302)
- **http2: code cleanup for http2_normalize_host** (9d5230e)
- **suricata: bound stack trace formatting in signal handler** (14eb3d3)
- **doc/bytemath: document the result of wide shifts** (d22b91c)
- **detect/bytemath: warn on literal shift counts of 64** (a400229)
- **detect/bytemath: guard right shift against wide counts** (2a06dcb)
- **affinity: handle NULL set name from --set affinity path** (c5e7b77)
- **firewall: validate action scope against the hook class** (c6ba237)
- **firewall: share the generic app hook name helper** (400e750)
- **github-ci: update fedora 42 builds to fedora 44** (c3134d4)
- **fuzz: use heap threadvars allocations** (4b3ad70)
- **detect/threshold: don't double init per thread cache** (8b665b1)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/OISF/suricata?utm_source=github-action)._