CVE-2025-59148

Source
https://cve.org/CVERecord?id=CVE-2025-59148
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59148.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-59148
Aliases
  • GHSA-5qf6-92xg-3rr3
Downstream
Related
Published
2025-10-01T19:51:27.388Z
Modified
2026-07-15T15:53:45.213073Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Suricata's improper use of entropy keyword can lead to a NULL-ptr deref
Details

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 8.0.0 and below incorrectly handle the entropy keyword when not anchored to a "sticky" buffer, which can lead to a segmentation fault. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules using the entropy keyword, or validate they are anchored to a sticky buffer.

Database specific
{
    "cwe_ids": [
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59148.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/oisf/suricata

Affected ranges

Type
GIT
Repo
https://github.com/oisf/suricata
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:oisf:suricata:8.0.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:oisf:suricata:8.0.0:beta1:*:*:*:*:*:*",
        "cpe:2.3:a:oisf:suricata:8.0.0:rc1:*:*:*:*:*:*"
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "8.0.0-NA"
        },
        {
            "last_affected": "8.0.0-NA"
        },
        {
            "introduced": "8.0.0-beta1"
        },
        {
            "last_affected": "8.0.0-beta1"
        },
        {
            "introduced": "8.0.0-rc1"
        },
        {
            "last_affected": "8.0.0-rc1"
        }
    ]
}

Affected versions

8.*
8.0.0-NA
8.0.0-beta1
8.0.0-rc1
suricata-8.*
suricata-8.0.0

Database specific

vanir_signatures_modified
"2026-07-15T15:53:45Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "target": {
            "file": "src/detect-engine-content-inspection.c"
        },
        "deprecated": false,
        "source": "https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c",
        "id": "CVE-2025-59148-14946a77",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "21994248850537563957592372885978420423",
                "288760675843925291579200991797569679237",
                "24970644708703577784961959675742721257",
                "212658837944025481167900626933605443404"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "src/detect-engine-content-inspection.c",
            "function": "DetectEngineContentInspectionInternal"
        },
        "deprecated": false,
        "source": "https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c",
        "id": "CVE-2025-59148-2ca7afb0",
        "signature_version": "v1",
        "digest": {
            "function_hash": "108980733906464721078256858831830580654",
            "length": 14825.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "src/detect-entropy.h"
        },
        "deprecated": false,
        "source": "https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c",
        "id": "CVE-2025-59148-61920ccf",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "291302231290099680989713245877011825059",
                "245001592688780976916397194216502957683"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "src/detect-entropy.c",
            "function": "DetectEntropySetup"
        },
        "deprecated": false,
        "source": "https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c",
        "id": "CVE-2025-59148-a6243f9c",
        "signature_version": "v1",
        "digest": {
            "function_hash": "332674278767820836016681022552225796486",
            "length": 635.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "src/detect-entropy.c",
            "function": "DetectEntropyDoMatch"
        },
        "deprecated": false,
        "source": "https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c",
        "id": "CVE-2025-59148-d49dd3ed",
        "signature_version": "v1",
        "digest": {
            "function_hash": "180129084752941587983283627185891771566",
            "length": 344.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "src/detect-entropy.c"
        },
        "deprecated": false,
        "source": "https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c",
        "id": "CVE-2025-59148-d91bd590",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "166510136999939649948594518036148589686",
                "240005701349172382665757262222362035883",
                "329004024159370148966796230572538553881",
                "96836684771520623133589282904312423395",
                "279499821950713529137027309076539867864",
                "164367828274321763679754641100102308498",
                "91177509203553275851947514980904192104",
                "258138023089753076198656443313910490859",
                "287693881910929089665783032195025169856",
                "143864411085767153610972376718916959768",
                "254904629661114744815213447983147628432",
                "168436807708941414077864947087946288704",
                "309115242476089587626410381373156691762",
                "18338237114265129813306724413851052044",
                "15425444460228091462828983115553663546",
                "301554270825557092952530395298111196283",
                "260370759430179776266883116658350655502",
                "209390108204982249289822173854327412954",
                "75460552066041514100803484349135907970"
            ],
            "threshold": 0.9
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59148.json"