CVE-2025-64334

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
GitHub_MCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Debian logo
Debian Releases
Debian Product
Codename
suricata
bullseye
1:6.0.1-3
not-affected
trixie
1:7.0.10-1+deb13u1
not-affected
bookworm
1:6.0.10-1
not-affected
bullseye (security)
1:6.0.1-3+deb11u1
fixed
forky
1:8.0.2-1
fixed
sid
1:8.0.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
suricata
questing
needs-triage
plucky
needs-triage
noble
needs-triage
jammy
needs-triage
bionic
needs-triage
xenial
needs-triage