CNNVD-202510-019 Information

CNNVD ID

CNNVD-202510-019

CVE-2025-59148

  • CNNVD Published: 2025-10-01

Description (Chinese)

Suricata是Open Information Security基金会的一个网络IDS、IPS和NSM引擎。 Suricata 8.0.0及之前版本存在代码问题漏洞,该漏洞源于未锚定到粘性缓冲区时错误处理熵关键字,可能导致分段错误。

Description (English)

Suricata is a web-based IDS, IPS and NSM engine of the Open Information Security Foundation. Suricata 8.0.0 and previous versions had a code gap, which stemmed from the error in the processing of entropy keys when unattended to a viscous buffer zone, which could lead to a split error.

Hazard Level

Medium

Vulnerability Type

代码问题

Affected Vendor

Open Information Security

Published

2025-10-01

Last Modified

2026-02-24

References

https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018 https://github.com/OISF/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c https://github.com/OISF/suricata/security/advisories/GHSA-5qf6-92xg-3rr3 https://redmine.openinfosecfoundation.org/issues/7838

Patch

https://suricata.io/

Share on: