Unrated severityNVD Advisory· Published Apr 10, 2025· Updated Apr 10, 2025
Suricata datasets: ruleset declared settings can lead to resource starvation
CVE-2025-29916
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the hashsize to use. This size setting isn't properly limited, so the hash table allocation can be large. Untrusted rules can lead to large memory allocations, potentially leading to denial of service due to resource starvation. This vulnerability is fixed in 7.0.9.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/OISF/suricata/commit/a7713db709b8a0be5fc5e5809ab58e9b14a16e85mitrex_refsource_MISC
- github.com/OISF/suricata/security/advisories/GHSA-27g3-pmvp-j9cvmitrex_refsource_CONFIRM
- redmine.openinfosecfoundation.org/issues/7615mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.