CVE-2025-64333: Suricata is vulnerable to a stack overflow from big content-type
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a large HTTP content type, when logged can cause a stack overflow crashing Suricata. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves limiting stream.reassembly.depth to less then half the stack size. Increasing the process stack size makes it less likely the bug will trigger.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64333?
CVE-2025-64333 is classified as a high severity vulnerability due to the potential for stack overflow that can crash Suricata.
How do I fix CVE-2025-64333?
To fix CVE-2025-64333, upgrade Suricata to version 7.0.13 or later, or to version 8.0.2 or later.
Which versions of Suricata are affected by CVE-2025-64333?
Suricata versions prior to 7.0.13 and 8.0.2 are affected by CVE-2025-64333.
What happens if I do not address CVE-2025-64333?
If CVE-2025-64333 is not addressed, there is a risk of Suricata crashing due to a stack overflow when handling large HTTP content types.
Is CVE-2025-64333 a vulnerability in any other software?
CVE-2025-64333 specifically affects the Suricata software developed by OISF and does not apply to other software.