CVE-2025-29916: Suricata datasets: ruleset declared settings can lead to resource starvation
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the hashsize to use. This size setting isn't properly limited, so the hash table allocation can be large. Untrusted rules can lead to large memory allocations, potentially leading to denial of service due to resource starvation. This vulnerability is fixed in 7.0.9.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29916?
CVE-2025-29916 has a severity level that indicates a potential impact on network performance due to improper handling of hash table sizes.
How do I fix CVE-2025-29916?
To fix CVE-2025-29916, you should update Suricata to version 7.0.9 or later, where the vulnerability has been addressed.
What software is affected by CVE-2025-29916?
The affected software for CVE-2025-29916 is Suricata versions prior to 7.0.9.
What is the impact of CVE-2025-29916 on systems?
The impact of CVE-2025-29916 may include excessive memory allocation, potentially leading to denial-of-service conditions.
How can I mitigate the risks associated with CVE-2025-29916?
To mitigate the risks of CVE-2025-29916, ensure that your Suricata deployment is regularly updated and monitor system performance closely.