CVE-2025-59150: Suricata: Keyword tls.subjectaltname can lead to NULL-ptr deref

Published Oct 1, 2025
·
Updated

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Version 8.0.0's usage of the tls.subjectaltname keyword can lead to a segmentation fault when the decoded subjectaltname contains a NULL byte. This issue is fixed in version 8.0.1. To workaround this issue, disable rules using the tls.subjectaltname keyword.

Affected Software

2 affected components
OISF Suricata=8.0.0
OISF Suricata=8.0.0

Event History

Oct 1, 2025
CVE Published
via MITRE·08:23 PM
Data Sourced
via MITRE·08:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-59150?

CVE-2025-59150 has been classified as a medium severity vulnerability due to its potential to cause a segmentation fault.

2

How do I fix CVE-2025-59150?

To fix CVE-2025-59150, you should upgrade to Suricata version 8.0.1 or later, which contains the necessary patches.

3

Which version of Suricata is affected by CVE-2025-59150?

Suricata version 8.0.0 is the only version known to be affected by CVE-2025-59150.

4

What conditions lead to the exploitation of CVE-2025-59150?

CVE-2025-59150 can be exploited if the decoded subjectaltname from TLS contains a NULL byte.

5

Is CVE-2025-59150 related to network security issues?

Yes, CVE-2025-59150 is related to a vulnerability in Suricata, which is a network IDS and IPS, affecting its ability to handle TLS subjectaltname decoding.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203