CVE-2025-64331

7.5

OISF · Suricata

A stack-based buffer overflow exists in Suricata prior to versions 7.0.13 and 8.0.2, triggered during large HTTP file transfers when specific logging and response limit configurations are enabled.

Executive summary

A stack-based buffer overflow in the Suricata network engine allows unauthenticated remote attackers to cause a denial of service condition.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) that occurs when processing large HTTP file transfers if the HTTP response body limit is increased and printable HTTP body logging is enabled. The vulnerability is remotely exploitable by an unauthenticated attacker.

Business impact

The exploitation of this vulnerability results in a denial of service, potentially crashing the Suricata inspection engine. Given that Suricata is often deployed as a critical security control (IDS/IPS), a successful crash could leave the network environment unprotected, significantly increasing the risk of unmonitored malicious activity. With a CVSS score of 7.5, this is classified as a High severity issue requiring prompt attention to maintain network visibility and security posture.

Remediation

Immediate Action: Update Suricata installations to version 7.0.13 or 8.0.2 immediately to incorporate the vendor-supplied security patches.

Proactive Monitoring: Review system logs for unexpected process crashes or service restarts that may indicate attempted exploitation of the buffer overflow.

Compensating Controls: If patching cannot be performed immediately, mitigate the risk by reverting HTTP response body limits to default values and disabling http-body-printable logging, which is not enabled by default.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to network monitoring infrastructure, particularly for organizations that have customized their Suricata configurations for deep packet inspection. Administrators should prioritize the application of the official patches provided by OISF. If immediate patching is not feasible, the recommended configuration changes should be implemented to reduce the attack surface until the software can be updated.

Sources