Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the `hashsize` to use. This size setting isn't properly limited, so the hash table allocation can be large. Untrusted rules can lead to large memory allocations, potentially leading to denial of service due to resource starvation. This vulnerability is fixed in 7.0.9.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 10 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the `hashsize` to use. This size setting isn't properly limited, so the hash table allocation can be large. Untrusted rules can lead to large memory allocations, potentially leading to denial of service due to resource starvation. This vulnerability is fixed in 7.0.9. | |
Title | Suricata datasets: ruleset declared settings can lead to resource starvation | |
Weaknesses | CWE-770 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-10T20:03:16.834Z
Updated: 2025-04-10T20:21:27.471Z
Reserved: 2025-03-12T13:42:22.135Z
Link: CVE-2025-29916

Updated: 2025-04-10T20:21:01.652Z

Status : Awaiting Analysis
Published: 2025-04-10T20:15:23.733
Modified: 2025-04-11T15:39:52.920
Link: CVE-2025-29916

No data.