Heap Overflow Vulnerability in Suricata Network IDS and IPS Engine
CVE-2025-64330
7.5HIGH
What is CVE-2025-64330?
Prior to the release of versions 7.0.13 and 8.0.2, Suricata was prone to a heap overflow vulnerability when logging verdicts in eve.alert and eve.drop records. This issue arises from a single byte read that can lead to crashes when the per packet alert queue is filled with alerts, subsequently followed by a pass rule. Users are advised to update to the latest versions and increase the alert queue size in the suricata.yaml configuration file if verdict logging is enabled to mitigate the risk of this potentially disruptive behavior.
Affected Version(s)
suricata < 7.0.13 < 7.0.13
suricata < 8.0.2 < 8.0.2
