Network IDS Vulnerability in Suricata by Open Information Security Foundation
CVE-2025-59148
7.5HIGH
What is CVE-2025-59148?
Suricata, a network intrusion detection and prevention system developed by the Open Information Security Foundation, is vulnerable in versions 8.0.0 and earlier due to improper handling of the entropy keyword when it is not associated with a 'sticky' buffer. This flaw can lead to a segmentation fault, affecting the application stability and performance. Users are advised to upgrade to version 8.0.1 to mitigate this vulnerability or disable rules that employ the entropy keyword while ensuring they are anchored to a sticky buffer as a temporary workaround.
Affected Version(s)
suricata < 8.0.1