Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-64330

Опубликовано: 26 нояб. 2025
Источник: debian

Описание

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a single byte read heap overflow when logging the verdict in eve.alert and eve.drop records can lead to crashes. This requires the per packet alert queue to be filled with alerts and then followed by a pass rule. This issue has been patched in versions 7.0.13 and 8.0.2. To reduce the likelihood of this issue occurring, the alert queue size a should be increased (packet-alert-max in suricata.yaml) if verdict is enabled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatafixed1:8.0.2-1package
suricatafixed1:7.0.10-1+deb13u2trixiepackage
suricatano-dsabookwormpackage
suricatanot-affectedbullseyepackage

Примечания

  • https://github.com/OISF/suricata/security/advisories/GHSA-83v7-gm34-f437

  • https://redmine.openinfosecfoundation.org/issues/8021 (private)

  • Fixed by: https://github.com/OISF/suricata/commit/482e5eac9218d007adbe2410d6c00173368ce947 (suricata-8.0.2)

  • Fixed by: https://github.com/OISF/suricata/commit/5d6c24cc2ce6a390c0956b7ecb2c5efc47e72abc (suricata-7.0.13)

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a single byte read heap overflow when logging the verdict in eve.alert and eve.drop records can lead to crashes. This requires the per packet alert queue to be filled with alerts and then followed by a pass rule. This issue has been patched in versions 7.0.13 and 8.0.2. To reduce the likelihood of this issue occurring, the alert queue size a should be increased (packet-alert-max in suricata.yaml) if verdict is enabled.

CVSS3: 7.5
nvd
2 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a single byte read heap overflow when logging the verdict in eve.alert and eve.drop records can lead to crashes. This requires the per packet alert queue to be filled with alerts and then followed by a pass rule. This issue has been patched in versions 7.0.13 and 8.0.2. To reduce the likelihood of this issue occurring, the alert queue size a should be increased (packet-alert-max in suricata.yaml) if verdict is enabled.

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость системы обнаружения и предотвращения вторжений Suricata, связанная с переполнением буфера в динамической памяти при обработке записей eve.alertи eve.drop, позволяющая нарушителю вызвать отказ в обслуживании