Skip to main content
Vulnerability Database/CVE-2025-59149

CVE-2025-59149: Oisf Suricata Buffer Overflow Vulnerability

CVE-2025-59149 is a stack buffer overflow flaw in Oisf Suricata network IDS/IPS engine affecting version 8.0.0. Rules using ldap.responses.attribute_type with transforms trigger this issue during startup or reload. This article covers technical details, affected versions, security impact, and mitigation strategies.

Updated:

CVE-2025-59149 Overview

CVE-2025-59149 is a stack buffer overflow vulnerability [CWE-121] in Suricata, the open-source network intrusion detection, prevention, and monitoring engine maintained by the Open Information Security Foundation (OISF). The flaw affects Suricata version 8.0.0 when rules use the ldap.responses.attribute_type keyword combined with transforms. The long attribute-type value overruns a fixed-size stack buffer inside the string shortener helper during Suricata startup or rule reload. Successful triggering aborts the engine, disrupting network monitoring and inline protection. OISF released a fix in Suricata 8.0.1.

Critical Impact

A malformed or overly long rule containing ldap.responses.attribute_type with transforms crashes Suricata at startup or reload, causing loss of IDS/IPS coverage on the affected sensor.

Affected Products

  • Suricata 8.0.0 (release)
  • Suricata 8.0.0-beta1
  • Suricata 8.0.0-rc1

Discovery Timeline

  • 2025-10-01 - CVE-2025-59149 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-59149

Vulnerability Analysis

Suricata parses detection rules at engine startup and during live rule reloads. When a rule references the ldap.responses.attribute_type keyword together with one or more transforms, the rule parser passes the attribute-type string through an internal string shortener utility in src/util-misc.c. The shortener copies content into a fixed-size stack buffer without validating that the source length fits. Because LDAP attribute-type identifiers can be substantially longer than the destination, the copy writes past the buffer boundary and corrupts adjacent stack memory. The result is a process crash and loss of network visibility on the sensor.

Root Cause

The root cause is missing length validation in the string shortener helper used by rule keyword processing. The function assumed inputs fit the destination buffer. When invoked against long LDAP attribute-type values combined with transform pipelines, it produced an out-of-bounds stack write [CWE-121].

Attack Vector

Exploitation is local and requires the presence of a rule that uses ldap.responses.attribute_type with a transform. An operator loading a crafted or malformed rule set, or a compromised rule-distribution channel delivering such content, triggers the overflow when Suricata parses the ruleset. The impact is limited to availability of the Suricata process.

c
// Patch excerpt from src/util-misc.c - "misc: harden string shortener"
 #include "util-debug.h"
 #include "util-unittest.h"
 #include "util-misc.h"
+#include "util-validate.h"

 #define PARSE_REGEX "^\\s*(\\d+(?:.\\d+)?)\\s*([a-zA-Z]{2,3})?\\s*$"
 static pcre2_code *parse_regex = NULL;
// Source: https://github.com/OISF/suricata/commit/38a2cba5c397002047d84645f5ab770ff88020e1

The upstream commit adds util-validate.h and hardens the shortener with input validation macros to prevent out-of-bounds writes.

Detection Methods for CVE-2025-59149

Indicators of Compromise

  • Unexpected Suricata process termination or SIGSEGV / SIGABRT events logged in suricata.log during startup or rule reload.
  • Rule files containing the ldap.responses.attribute_type keyword paired with transform modifiers such as to_lowercase, strip_whitespace, or dotprefix.
  • Rule reload cycles that succeed on prior versions but crash on Suricata 8.0.0.

Detection Strategies

  • Inventory deployed Suricata sensors and enumerate versions using suricata --build-info to identify 8.0.0 hosts.
  • Grep loaded rule sets for the pattern ldap.responses.attribute_type combined with any transform keyword to locate at-risk rules.
  • Correlate sensor availability telemetry with rule-reload timestamps to spot crash-on-reload behavior.

Monitoring Recommendations

  • Alert on Suricata service restarts, coredumps, and abnormal exits from process monitoring or systemd unit status.
  • Monitor rule-management pipelines (Suricata-Update, custom feeds) for introduction of LDAP response attribute-type rules.
  • Track sensor packet-processing gaps that align with configuration deployments to detect availability loss.

How to Mitigate CVE-2025-59149

Immediate Actions Required

  • Upgrade all Suricata 8.0.0 deployments to version 8.0.1 or later, which contains the hardened string shortener.
  • Audit active rule sets for ldap.responses.attribute_type combined with transforms and disable those rules until the upgrade is applied.
  • Validate rule sets in a staging sensor before pushing to production to avoid crash-on-reload outages.

Patch Information

OISF fixed the issue in Suricata 8.0.1. The upstream fix is available in the Suricata Commit Details and described in the GitHub Security Advisory. Release notes are published in the Suricata Release Announcement, and tracking is available in the Open Information Security Issue.

Workarounds

  • Disable any rule that combines ldap.responses.attribute_type with transforms until the sensor is patched.
  • Restrict rule-update sources to trusted feeds and require review before rule reloads on 8.0.0 hosts.
  • Roll back affected sensors to Suricata 7.0.x if upgrading to 8.0.1 is not immediately feasible.
bash
# Identify at-risk rules in the Suricata rules directory
grep -RIn --include='*.rules' -E 'ldap\.responses\.attribute_type.*(to_lowercase|strip_whitespace|dotprefix|compress_whitespace|url_decode)' /etc/suricata/rules/

# Verify installed Suricata version
suricata --build-info | grep -i 'version'

# Test rule set before reload
suricata -T -c /etc/suricata/suricata.yaml -v

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.