Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the `hashsize` to use. This size setting isn't properly limited, so the hash table allocation can be large. Untrusted rules can lead to large memory allocations, potentially leading to denial of service due to resource starvation. This vulnerability is fixed in 7.0.9.
History

Thu, 29 May 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
Vendors & Products Oisf
Oisf suricata

Thu, 10 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the `hashsize` to use. This size setting isn't properly limited, so the hash table allocation can be large. Untrusted rules can lead to large memory allocations, potentially leading to denial of service due to resource starvation. This vulnerability is fixed in 7.0.9.
Title Suricata datasets: ruleset declared settings can lead to resource starvation
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-10T20:03:16.834Z

Updated: 2025-04-10T20:21:27.471Z

Reserved: 2025-03-12T13:42:22.135Z

Link: CVE-2025-29916

cve-icon Vulnrichment

Updated: 2025-04-10T20:21:01.652Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-10T20:15:23.733

Modified: 2025-05-29T15:48:21.190

Link: CVE-2025-29916

cve-icon Redhat

No data.