PT-2025-48205 · Open Information Security Foundation+2 · Suricata+2

Published

2025-11-05

·

Updated

2026-01-22

·

CVE-2025-64332

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 7.0.13 Suricata versions prior to 8.0.2
Description Suricata is a network IDS, IPS and NSM engine. Versions of Suricata prior to 7.0.13 and 8.0.2 are susceptible to a stack overflow that can cause the software to crash when SWF decompression is enabled. A workaround involves disabling SWF decompression in the suricata.yaml file (swf-decompression). If SWF decompression must be enabled, set the decompress-depth to a value less than half of the system's stack size.
Recommendations Update Suricata to version 7.0.13 or later. Update Suricata to version 8.0.2 or later. Disable SWF decompression by setting swf-decompression to false in the suricata.yaml file. If SWF decompression must be enabled, set the decompress-depth to a value less than half of the system's stack size.

Exploit

Fix

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14099
BDU:2025-15198
CVE-2025-64332
GHSA-P32Q-7WCP-GV92
OPENSUSE-SU-2026:10082-1

Affected Products

Alt Linux
Debian
Suricata