Stack Overflow Risk in Suricata Network Engine by Open Information Security Foundation
CVE-2025-64333

7.5HIGH

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
26 November 2025

What is CVE-2025-64333?

A vulnerability has been identified in the Suricata network intrusion detection and prevention system, where processing a large HTTP content type can trigger a stack overflow. This effect can lead to the unexpected crashing of the Suricata engine. Users of Suricata versions prior to 7.0.13 and 8.0.2 are particularly affected. To mitigate the risk, it is recommended to limit the 'stream.reassembly.depth' setting to less than half of the stack size, and consider increasing the stack size to reduce the likelihood of triggering this issue. The vulnerability has been addressed in the updated versions.

Affected Version(s)

suricata < 7.0.13 < 7.0.13

suricata < 8.0.2 < 8.0.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64333 : Stack Overflow Risk in Suricata Network Engine by Open Information Security Foundation