CVE-2025-59148: Suricata's improper use of entropy keyword can lead to a NULL-ptr deref
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 8.0.0 and below incorrectly handle the entropy keyword when not anchored to a "sticky" buffer, which can lead to a segmentation fault. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules using the entropy keyword, or validate they are anchored to a sticky buffer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59148?
CVE-2025-59148 has a severity rating that reflects the potential for inducing a segmentation fault in Suricata, impacting its stability.
How do I fix CVE-2025-59148?
To fix CVE-2025-59148, upgrade to Suricata version 8.0.1 or higher.
Which versions of Suricata are affected by CVE-2025-59148?
CVE-2025-59148 affects Suricata versions 8.0.0 and below.
What causes the vulnerability in CVE-2025-59148?
CVE-2025-59148 is caused by improper handling of the entropy keyword when not anchored to a sticky buffer.
Can CVE-2025-59148 lead to a security breach?
While CVE-2025-59148 primarily leads to a segmentation fault, it can potentially disrupt service availability.