CVE-2025-64334Allocation of Resources Without Limits or Throttling in Suricata

Severity
7.5HIGHNVD
EPSS
0.1%
top 84.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 26

Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDoisf/suricata8.0.08.0.2
Debianoisf/suricata< 1:8.0.2-1
CVEListV5oisf/suricata>= 8.0.0, < 8.0.2

Patches

🔴Vulnerability Details

2
OSV
CVE-2025-64334: Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community2025-11-26
CVEList
Suricata is vulnerable to unbounded memory growth for decompression2025-11-26

📋Vendor Advisories

2
Red Hat
Suricata: Suricata: Unbounded memory growth via compressed HTTP data2025-11-26
Debian
CVE-2025-64334: suricata - Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform...2025
CVE-2025-64334 — Oisf Suricata vulnerability | cvebase