Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-64334

Опубликовано: 26 нояб. 2025
Источник: redhat
CVSS3: 7.5

Описание

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.

A flaw was found in Suricata. This vulnerability allows unbounded memory growth during decompression via compressed HTTP data.

Отчет

The highest threat is to system availability due to unbounded memory growth when processing compressed HTTP data. This issue affects Suricata when configured to inspect HTTP traffic that includes compressed content.

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2417387Suricata: Suricata: Unbounded memory growth via compressed HTTP data

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.

CVSS3: 7.5
nvd
4 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.

CVSS3: 7.5
debian
4 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (O ...

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость системы обнаружения и предотвращения вторжений Suricata, связанная с распределением ресурсов без ограничений и регулирования, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3