CVE-2025-64332: Suricata is vulnerable to a stack overflow on larger compressed data
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow that causes Suricata to crash can occur if SWF decompression is enabled. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling SWF decompression (swf-decompression in suricata.yaml), it is disabled by default; set decompress-depth to lower than half your stack size if swf-decompression must be enabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64332?
CVE-2025-64332 is a high severity vulnerability due to the potential for remote code execution resulting from the stack overflow.
How do I fix CVE-2025-64332?
To fix CVE-2025-64332, upgrade Suricata to version 7.0.13 or later, or to version 8.0.2 or later.
What are the affected versions of Suricata for CVE-2025-64332?
Affected versions of Suricata for CVE-2025-64332 are prior to 7.0.13 and prior to 8.0.2.
What causes CVE-2025-64332 to occur?
CVE-2025-64332 is triggered when SWF decompression is enabled, leading to a stack overflow that causes Suricata to crash.
Is there a workaround for CVE-2025-64332?
A temporary workaround for CVE-2025-64332 is to disable SWF decompression until the software can be upgraded.