Vulnerability Description
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Version 8.0.0's usage of the tls.subjectaltname keyword can lead to a segmentation fault when the decoded subjectaltname contains a NULL byte. This issue is fixed in version 8.0.1. To workaround this issue, disable rules using the tls.subjectaltname keyword.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oisf | Suricata | 8.0.0 |
Related Weaknesses (CWE)
References
- https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018Release Notes
- https://github.com/OISF/suricata/commit/d590fdfe42e995fd558315f0c24f9a352e21479dPatch
- https://github.com/OISF/suricata/security/advisories/GHSA-mhv7-qfmj-m3f3PatchThird Party Advisory
- https://redmine.openinfosecfoundation.org/issues/7881ExploitIssue TrackingVendor Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-59150-suricata-detection-script
- https://www.vicarius.io/vsociety/posts/cve-2025-59150-suricata-mitigation-script
FAQ
What is CVE-2025-59150?
CVE-2025-59150 is a vulnerability with a CVSS score of 7.5 (HIGH). Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Version 8.0.0's usage of the tls.subjectaltname keyword can lead ...
How severe is CVE-2025-59150?
CVE-2025-59150 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59150?
Check the references section above for vendor advisories and patch information. Affected products include: Oisf Suricata.