CVE-2025-59147

NameCVE-2025-59147
DescriptionSuricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 7.0.11 and below, as well as 8.0.0, are vulnerable to detection bypass when crafted traffic sends multiple SYN packets with different sequence numbers within the same flow tuple, which can cause Suricata to fail to pick up the TCP session. In IDS mode this can lead to a detection and logging bypass. In IPS mode this will lead to the flow getting blocked. This issue is fixed in versions 7.0.12 and 8.0.1.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
suricata (PTS)bullseye1:6.0.1-3vulnerable
bullseye (security)1:6.0.1-3+deb11u1vulnerable
bookworm1:6.0.10-1vulnerable
trixie1:7.0.10-1vulnerable
forky, sid1:8.0.1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
suricatasource(unstable)1:8.0.1-1

Notes

[trixie] - suricata <no-dsa> (Minor issue)
[bookworm] - suricata <no-dsa> (Minor issue)
https://github.com/OISF/suricata/security/advisories/GHSA-v8hv-6v7x-4c2r
https://github.com/OISF/suricata/commit/be6315dba0d9101b11d16e9dacfe2822b3792f1b (suricata-8.0.1)
https://github.com/OISF/suricata/commit/e91b03c90385db15e21cf1a0e85b921bf92b039e (suricata-7.0.12)
https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018

Search for package or bug name: Reporting problems