Heap Overflow Vulnerability in Suricata Network IDS and IPS Engine
CVE-2025-64330

7.5HIGH

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
26 November 2025

What is CVE-2025-64330?

Prior to the release of versions 7.0.13 and 8.0.2, Suricata was prone to a heap overflow vulnerability when logging verdicts in eve.alert and eve.drop records. This issue arises from a single byte read that can lead to crashes when the per packet alert queue is filled with alerts, subsequently followed by a pass rule. Users are advised to update to the latest versions and increase the alert queue size in the suricata.yaml configuration file if verdict logging is enabled to mitigate the risk of this potentially disruptive behavior.

Affected Version(s)

suricata < 7.0.13 < 7.0.13

suricata < 8.0.2 < 8.0.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.