Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Version 8.0.0's usage of the tls.subjectaltname keyword can lead to a segmentation fault when the decoded subjectaltname contains a NULL byte. This issue is fixed in version 8.0.1. To workaround this issue, disable rules using the tls.subjectaltname keyword.
References
Configurations
History
23 Oct 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () https://redmine.openinfosecfoundation.org/issues/7881 - Exploit, Issue Tracking, Vendor Advisory |
06 Oct 2025, 15:46
Type | Values Removed | Values Added |
---|---|---|
First Time |
Oisf
Oisf suricata |
|
CPE | cpe:2.3:a:oisf:suricata:8.0.0:*:*:*:*:*:*:* | |
References | () https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018 - Release Notes | |
References | () https://github.com/OISF/suricata/commit/d590fdfe42e995fd558315f0c24f9a352e21479d - Patch | |
References | () https://github.com/OISF/suricata/security/advisories/GHSA-mhv7-qfmj-m3f3 - Patch, Third Party Advisory | |
References | () https://redmine.openinfosecfoundation.org/issues/7881 - Issue Tracking, Exploit, Vendor Advisory |
01 Oct 2025, 21:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-01 21:16
Updated : 2025-10-23 14:15
NVD link : CVE-2025-59150
Mitre link : CVE-2025-59150
CVE.ORG link : CVE-2025-59150
JSON object : View
Products Affected
oisf
- suricata
CWE
CWE-476
NULL Pointer Dereference