CVE-2025-64334
Published: 11/26/2025 23:15:48
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.
HIGH
CVSS v3: 7.5
CVSS v3: 7.5
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 22.3 | lzma (17.01) | Needs Triage | ||
| 22.2 | lzma (17.01) | Needs Triage | ||
| 22.1 | lzma (17.01) | Needs Triage | ||
| 21.11.1 | lzma (17.01) | Needs Triage | ||
| 21.11 | lzma (17.01) | Needs Triage | ||
| 21.8.1 | lzma (17.01) | Needs Triage | ||
| 21.8 | lzma (17.01) | Needs Triage | ||
| 21.5.1 | lzma (17.01) | Needs Triage | ||
| 21.5.0 | lzma (17.01) | Needs Triage | ||
| 21.2.0 | lzma (17.01) | Needs Triage | ||
| 11.4.20 | lzma (17.01) | Needs Triage | ||
| 11.4.19.3667 | lzma (17.01) | Needs Triage | ||
| 11.4.18.3599 | lzma (17.01) | Needs Triage | ||
| 11.4.17 | lzma (17.01) | Needs Triage | ||
| 11.4.16.3445 | lzma (17.01) | Needs Triage | ||
| 11.4.15.3368 | lzma (17.01) | Needs Triage | ||
| 11.4.14.3263 | lzma (17.01) | Needs Triage | ||
| 11.4.13.3179 | lzma (17.01) | Needs Triage | ||
| 11.4.12.3054 | lzma (17.01) | Needs Triage | ||
| 11.4.11.3040 | lzma (17.01) | Needs Triage | ||
| 11.4.11.2990 | lzma (17.01) | Needs Triage | ||
| 11.4.10.2934 | lzma (17.01) | Needs Triage | ||
| 11.4.9.2878 | lzma (17.01) | Needs Triage | ||
| 11.4.8.2822 | lzma (17.01) | Needs Triage |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
7.5
Base Severity
HIGH
Confidentiality Impact
NONE
Integrity Impact
NONE
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Version
3.1