CVE-2025-59150
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Version 8.0.0's usage of the tls.subjectaltname keyword can lead to a segmentation fault when the decoded subjectaltname contains a NULL byte. This issue is fixed in version 8.0.1. To workaround this issue, disable rules using the tls.subjectaltname keyword.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- oisf/suricata
- Source
- security-advisories@github.com
References
- https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018Release Notes
- https://github.com/OISF/suricata/commit/d590fdfe42e995fd558315f0c24f9a352e21479dPatch
- https://github.com/OISF/suricata/security/advisories/GHSA-mhv7-qfmj-m3f3Patch, Third Party Advisory
- https://redmine.openinfosecfoundation.org/issues/7881Exploit, Issue Tracking, Vendor Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-59150-suricata-detection-script
- https://www.vicarius.io/vsociety/posts/cve-2025-59150-suricata-mitigation-script
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.