Vulnerability Description
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oisf | Suricata | >= 8.0.0, < 8.0.2 |
Related Weaknesses (CWE)
References
- https://github.com/OISF/suricata/commit/c935f08cd988600fd0a4f828a585b181dd5de012Patch
- https://github.com/OISF/suricata/security/advisories/GHSA-v299-h7p3-q4f2Third Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-64335-detect-suricata-vulnerabil
- https://www.vicarius.io/vsociety/posts/cve-2025-64335-mitigate-suricata-vulnerab
FAQ
What is CVE-2025-64335?
CVE-2025-64335 is a vulnerability with a CVSS score of 7.5 (HIGH). Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can oc...
How severe is CVE-2025-64335?
CVE-2025-64335 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64335?
Check the references section above for vendor advisories and patch information. Affected products include: Oisf Suricata.