CVE-2025-59149: Suricata: Stack buffer overflow in rule parser when processing long keywords with transforms
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In version 8.0.0, rules using keyword ldap.responses.attributetype (which is long) with transforms can lead to a stack buffer overflow during Suricata startup or during a rule reload. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules with ldap.responses.attributetype and transforms.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59149?
CVE-2025-59149 is rated as a high-severity vulnerability due to the potential for a stack buffer overflow.
How do I fix CVE-2025-59149?
To fix CVE-2025-59149, upgrade Suricata to version 8.0.1 or later.
What versions of Suricata are affected by CVE-2025-59149?
CVE-2025-59149 affects OISF Suricata versions prior to 8.0.1.
What causes CVE-2025-59149?
CVE-2025-59149 is caused by rules using the ldap.responses.attribute_type keyword with transforms leading to a stack buffer overflow.
Is there a workaround for CVE-2025-59149?
There are no known workarounds for CVE-2025-59149, the recommended action is to upgrade the software.