Heap Overflow Vulnerability in Suricata Network IDS and IPS Engine
CVE-2025-64330
What is CVE-2025-64330?
Prior to the release of versions 7.0.13 and 8.0.2, Suricata was prone to a heap overflow vulnerability when logging verdicts in eve.alert and eve.drop records. This issue arises from a single byte read that can lead to crashes when the per packet alert queue is filled with alerts, subsequently followed by a pass rule. Users are advised to update to the latest versions and increase the alert queue size in the suricata.yaml configuration file if verdict logging is enabled to mitigate the risk of this potentially disruptive behavior.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
suricata < 7.0.13 < 7.0.13
suricata < 8.0.2 < 8.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
