CVE-2025-59148: Oisf Suricata

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 8.0.0 and below incorrectly handle the entropy keyword when not anchored to a "sticky" buffer, which can lead to a segmentation fault. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules using the entropy keyword, or validate they are anchored to a sticky buffer.

Affected products

  • Oisf Suricata: version 8.0.0 only

Published 2025-10-01. Last modified 2026-06-17.