Suricata是Open Information Security基金会的一个网络IDS、IPS和NSM引擎。 Suricata 8.0.0版本存在代码问题漏洞,该漏洞源于解码subjectaltname包含空字节时使用tls.subjectaltname关键字,可能导致分段违规。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-59147 | 7.5 HIGH | Suricata is Vulnerable to Detection Bypass via Crafted Multiple SYN Packets |
| CVE-2025-59148 | 7.5 HIGH | Suricata's improper use of entropy keyword can lead to a NULL-ptr deref |
| CVE-2025-59149 | 6.2 MEDIUM | Suricata: Stack buffer overflow in rule parser when processing long keywords with transfor |
No comments yet