CVE-2025-29917

Name
CVE-2025-29917
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The bytes setting in the decode_base64 keyword is not properly limited. Due to this, signatures using the keyword and setting can cause large memory allocations of up to 4 GiB per thread. This vulnerability is fixed in 7.0.9.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/OISF/suricata/security/advisories/GHSA-x8c9-8553-j9px
MISC https://github.com/OISF/suricata/commit/32d0bd2bbb4d486623dec85a94952fde2515f2f0
MISC https://redmine.openinfosecfoundation.org/issues/7613

Match rules

CPE URI Source package Min version Max version
suricata >= 0 < 7.0.9
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* suricata >= None < 7.0.9

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
suricata edge-community 7.0.8-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata edge-community 7.0.7-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata 3.22-community 7.0.8-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable