CVE flood

37 views
Skip to first unread message

mt b

unread,
Sep 25, 2026, 10:44:50 AM (12 days ago) Sep 25
to Wazuh | Mailing List
Hello everyone!
I'm using Wazuh v.4.14.3 and i have 9 agent (all v.4.14.3) installed on ubuntu server 22.04 and 24.04 LTS. 
This day I recieved a flood of cve from 2 of them even for very old CVEs. 
The strage thing is that it was the activation of rule 23504 and after less two second the activation of rule 23502 for the same CVE and this for hundreds of CVEs.
Maybe those two agents lost the database of resolved CVEs?Or What?
Thank you in advance for all. 

Olamilekan Abdullateef Ajani

unread,
Sep 25, 2026, 11:28:50 AM (12 days ago) Sep 25
to Wazuh | Mailing List
Hello

Rule 23504 means Wazuh detected an active medium/untriaged vulnerability, while rule 23502 means it considered the vulnerability solved.

This does not necessarily mean the agents lost their database. Wazuh does not generate vulnerability alerts during the initial inventory synchronization, so you should first check whether package updates occurred on those two servers.

Choose one CVE and compare the complete JSON for both alerts, especially:

- data.vulnerability.package.name
- data.vulnerability.package.version
- data.vulnerability.package.architecture
- data.vulnerability.package.condition

If rule 23504 refers to a new package version and rule 23502 to the old version, a package upgrade probably triggered the alerts. Check the package history around that time too.

zgrep -hE ' (upgrade|install|remove) ' /var/log/dpkg.log*
zgrep -hE 'Start-Date|Upgrade:|Install:|Remove:' /var/log/apt/history.log*

Also check Vulnerability Detection > Inventory. The Events section contains the active/solved history, while Inventory shows the current state. If the CVE is no longer in Inventory, it has been resolved. If it is still present against the new package version, the system is still considered vulnerable.

If both alerts contain exactly the same package, version, and architecture, and there was no package activity, then this looks more like inventory or scanner state changing unexpectedly. In that case, check the manager log around the alert time:

grep -Ei 'vulnerability-scanner|content-updater|syscollector|indexer-connector|error|warning' /var/ossec/logs/ossec.log

A similar upgrade-related active/solved behavior was reported in an older version, you can also check them out below.

https://github.com/wazuh/wazuh/issues/13354
https://github.com/wazuh/wazuh/pull/17052

If possible, please share one complete 23504/23502 alert pair with the package details. That should make it clearer.

I await feedback from you.

mt b

unread,
Sep 25, 2026, 11:41:02 AM (12 days ago) Sep 25
to Wazuh | Mailing List
Hi! Thank you for the reply.
I think I understand what happend.
Those 2 system upgraded kernel and there are a great many CVEs that do not have a patch and so they are also in the new kernel.  
So Wazuh notified me of presence of these CVEs for the new kernel and after the old kernel was unistalled it nified me that they are gone with old kernel (but sitll present for the new one.) . 
And this will happen with every kernel change.
Could I be right?
Thank you so much.

Olamilekan Abdullateef Ajani

unread,
Sep 25, 2026, 1:16:00 PM (11 days ago) Sep 25
to Wazuh | Mailing List
Hello,

Yes, that is most likely what happened. Ubuntu kernel packages usually includes the kernel version in the package name. When the new kernel was installed, Wazuh detected the CVEs affecting that new package and generated the 23504 alerts. When the old kernel package was removed, Wazuh marked the findings associated with that old package as solved using rule 23502.

This means "Solved" does not necessarily mean that the CVE is gone from the whole system. It can mean that the specific old package associated with that finding is no longer installed, while the same CVE is still active for the new kernel package.

You can confirm this by comparing these fields in one 23504/23502 alert pair:

data.vulnerability.package.name
data.vulnerability.package.version

If 23504 refers to the new kernel and 23502 refers to the old one, then your explanation is correct. The current findings for the new kernel should still appear under Vulnerability Detection > Inventory.

It may not happen with every kernel change. It depends on whether the new kernel is also considered affected and whether the old kernel package is removed. Ubuntu sometimes keeps an older kernel installed as a fallback.

So, in this case, this does not mean that the agents lost their database.
Reply all
Reply to author
Forward
0 new messages