CNNVD-202510-020 Information

CNNVD ID

CNNVD-202510-020

CVE-2025-59147

  • CNNVD Published: 2025-10-01

Description (Chinese)

Suricata是Open Information Security基金会的一个网络IDS、IPS和NSM引擎。 Suricata 7.0.11及之前版本和8.0.0版本存在安全特征问题漏洞,该漏洞源于处理特制流量时未能正确识别TCP会话,可能导致检测绕过。

Description (English)

Suricata is a web-based IDS, IPS and NSM engine of the Open Information Security Foundation. Suricata 7.0.11 and previous versions and 8.0.0 have a security feature loophole, which stems from the failure to correctly identify TCP sessions while dealing with ad hoc traffic and may lead to detection circumvention.

Hazard Level

Medium

Vulnerability Type

安全特征问题

Affected Vendor

Open Information Security

Published

2025-10-01

Last Modified

2026-02-24

References

https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018 https://github.com/OISF/suricata/commit/be6315dba0d9101b11d16e9dacfe2822b3792f1b https://github.com/OISF/suricata/commit/e91b03c90385db15e21cf1a0e85b921bf92b039e https://github.com/OISF/suricata/security/advisories/GHSA-v8hv-6v7x-4c2r

Patch

https://suricata.io/

Share on: