Segmentation Fault Vulnerability in Suricata Network IDS by OISF
CVE-2025-59150
7.5HIGH
What is CVE-2025-59150?
The Suricata network IDS, IPS, and NSM engine, developed by the OISF, has a vulnerability in version 8.0.0 that can trigger a segmentation fault. This issue arises from the improper handling of the tls.subjectaltname keyword when the decoded subjectaltname contains a NULL byte. Users are advised to upgrade to version 8.0.1 to resolve this issue or temporarily disable rules that utilize the tls.subjectaltname keyword to prevent service interruptions.
Affected Version(s)
suricata >= 8.0.0, < 8.0.1