{
  "threat_severity" : "Important",
  "public_date" : "2025-11-26T22:59:28Z",
  "bugzilla" : {
    "description" : "Suricata: Suricata: Denial of service via SWF decompression",
    "id" : "2417410",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2417410"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-121",
  "details" : [ "Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow that causes Suricata to crash can occur if SWF decompression is enabled. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling SWF decompression (swf-decompression in suricata.yaml), it is disabled by default; set decompress-depth to lower than half your stack size if swf-decompression must be enabled.", "A flaw was found in Suricata. This vulnerability allows a denial of service (DoS) via SWF (Small Web Format) decompression." ],
  "statement" : "The highest threat of this flaw is to system availability. This issue only affects Suricata installations where SWF decompression is explicitly enabled, as it is disabled by default.",
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-64332\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-64332\nhttps://github.com/OISF/suricata/commit/ad446c9006a77490af51c468aae0ce934f4d2117\nhttps://github.com/OISF/suricata/security/advisories/GHSA-p32q-7wcp-gv92" ],
  "name" : "CVE-2025-64332",
  "csaw" : false
}