{"id":"CVE-2025-59148","summary":"Suricata's improper use of entropy keyword can lead to a NULL-ptr deref","details":"Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 8.0.0 and below incorrectly handle the entropy keyword when not anchored to a \"sticky\" buffer, which can lead to a segmentation fault. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules using the entropy keyword, or validate they are anchored to a sticky buffer.","aliases":["GHSA-5qf6-92xg-3rr3"],"modified":"2026-07-15T15:53:45.213073Z","published":"2025-10-01T19:51:27.388Z","related":["openSUSE-SU-2025:15592-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59148.json"},"references":[{"type":"WEB","url":"https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018"},{"type":"WEB","url":"https://redmine.openinfosecfoundation.org/issues/7838"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59148.json"},{"type":"ADVISORY","url":"https://github.com/OISF/suricata/security/advisories/GHSA-5qf6-92xg-3rr3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59148"},{"type":"FIX","url":"https://github.com/OISF/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oisf/suricata","events":[{"introduced":"9956286fb89f9cad9e9f95b99dc751f8666617b7"},{"fixed":"9f32550e18f97ea5d610dd7c36aab0ba142c096c"}],"database_specific":{"cpe":["cpe:2.3:a:oisf:suricata:8.0.0:-:*:*:*:*:*:*","cpe:2.3:a:oisf:suricata:8.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:oisf:suricata:8.0.0:rc1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.0-NA"},{"last_affected":"8.0.0-NA"},{"introduced":"8.0.0-beta1"},{"last_affected":"8.0.0-beta1"},{"introduced":"8.0.0-rc1"},{"last_affected":"8.0.0-rc1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["8.0.0-NA","8.0.0-beta1","8.0.0-rc1","suricata-8.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59148.json","vanir_signatures_modified":"2026-07-15T15:53:45Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c","target":{"file":"src/detect-engine-content-inspection.c"},"deprecated":false,"digest":{"line_hashes":["21994248850537563957592372885978420423","288760675843925291579200991797569679237","24970644708703577784961959675742721257","212658837944025481167900626933605443404"],"threshold":0.9},"id":"CVE-2025-59148-14946a77"},{"target":{"file":"src/detect-engine-content-inspection.c","function":"DetectEngineContentInspectionInternal"},"deprecated":false,"digest":{"function_hash":"108980733906464721078256858831830580654","length":14825},"id":"CVE-2025-59148-2ca7afb0","signature_type":"Function","signature_version":"v1","source":"https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c"},{"deprecated":false,"digest":{"line_hashes":["291302231290099680989713245877011825059","245001592688780976916397194216502957683"],"threshold":0.9},"id":"CVE-2025-59148-61920ccf","signature_type":"Line","signature_version":"v1","source":"https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c","target":{"file":"src/detect-entropy.h"}},{"target":{"file":"src/detect-entropy.c","function":"DetectEntropySetup"},"deprecated":false,"digest":{"function_hash":"332674278767820836016681022552225796486","length":635},"id":"CVE-2025-59148-a6243f9c","signature_type":"Function","signature_version":"v1","source":"https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c","target":{"file":"src/detect-entropy.c","function":"DetectEntropyDoMatch"},"deprecated":false,"digest":{"function_hash":"180129084752941587983283627185891771566","length":344},"id":"CVE-2025-59148-d49dd3ed"},{"digest":{"line_hashes":["166510136999939649948594518036148589686","240005701349172382665757262222362035883","329004024159370148966796230572538553881","96836684771520623133589282904312423395","279499821950713529137027309076539867864","164367828274321763679754641100102308498","91177509203553275851947514980904192104","258138023089753076198656443313910490859","287693881910929089665783032195025169856","143864411085767153610972376718916959768","254904629661114744815213447983147628432","168436807708941414077864947087946288704","309115242476089587626410381373156691762","18338237114265129813306724413851052044","15425444460228091462828983115553663546","301554270825557092952530395298111196283","260370759430179776266883116658350655502","209390108204982249289822173854327412954","75460552066041514100803484349135907970"],"threshold":0.9},"id":"CVE-2025-59148-d91bd590","signature_type":"Line","signature_version":"v1","source":"https://github.com/oisf/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c","target":{"file":"src/detect-entropy.c"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}