CVE-2025-64334

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
GitHub_MCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
oisfsuricata
8.0.0 ≤
𝑥
< 8.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
suricata
bullseye
1:6.0.1-3
not-affected
trixie
1:7.0.10-1+deb13u2
not-affected
bookworm
1:6.0.10-1
not-affected
bullseye (security)
1:6.0.1-3+deb11u1
fixed
forky
1:8.0.3-1
fixed
sid
1:8.0.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
suricata
questing
needs-triage
plucky
ignored
noble
needs-triage
jammy
needs-triage
bionic
needs-triage
xenial
needs-triage