CVE 7.5 HIGH

Suricata’s improper use of entropy keyword can lead to a NULL-ptr deref_CVE-2025-59148

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 8.0.0 and below incorrectly handle the entropy keyword when not anchored to a "sticky" buffer, which can lead to a segmentation fault. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules using the entropy keyword, or validate they are anchored to a sticky buffer.

Basic Information

ID CVE-2025-59148
Source GitHub_M
Published Oct 1, 2025 at 19:51
Modified Oct 1, 2025 at 19:58

Affected Product

Vendor OISF
Product suricata
Version < 8.0.1
Affected Versions OISF suricata < 8.0.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.