PT-2025-48204 · Open Information Security Foundation+2 · Suricata+2

CVE-2025-64331

·

Publicado

2025-11-06

·

Atualizado

2026-01-22

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 7.0.13 Suricata versions prior to 8.0.2
Description Suricata is a network IDS, IPS and NSM engine. A stack overflow can occur during large HTTP file transfers if the HTTP response body limit is increased and logging of printable HTTP bodies is enabled. The issue has been addressed in newer versions. A workaround involves using default HTTP response body limits and/or disabling http-body-printable logging, which is disabled by default.
Recommendations Update to Suricata version 7.0.13 or later. Update to Suricata version 8.0.2 or later. Use default HTTP response body limits. Disable http-body-printable logging.

Exploit

Correção

Memory Corruption

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-14099
BDU:2025-15197
CVE-2025-64331
GHSA-V32W-J79X-PFJ2
OPENSUSE-SU-2026:10082-1

Produtos afetados

Alt Linux
Debian
Suricata