Memory leak in libhtp - CVE-2025-53537
Published: July 24, 2025
Vulnerability identifier: #VU113190
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-53537
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service (DoS) attack on the target system.
The vulnerability exists due memory leak. A remote attacker can force the application to leak memory and perform denial of service attack.
Affected software
libhtp
Fedora
Ubuntu
libhtp (Ubuntu package)
suricata
Fedora
Ubuntu
libhtp (Ubuntu package)
suricata
How to mitigate CVE-2025-53537
Install updates from vendor's website.
libhtp - update to 0.5.51
libhtp (Ubuntu package) - addressed in versions 0.5.15-1ubuntu0.1~esm1, 1:0.5.26-1ubuntu0.1~esm1, 1:0.5.32-1ubuntu0.1~esm1, 1:0.5.39-1ubuntu0.1~esm1, 1:0.5.46-1ubuntu2+esm1, 1:0.5.49-1ubuntu0.1
suricata - addressed in versions 7.0.11-1.el8, 7.0.11-1.el9, 7.0.11-1.fc41, 7.0.11-1.fc42
libhtp (Ubuntu package) - addressed in versions 0.5.15-1ubuntu0.1~esm1, 1:0.5.26-1ubuntu0.1~esm1, 1:0.5.32-1ubuntu0.1~esm1, 1:0.5.39-1ubuntu0.1~esm1, 1:0.5.46-1ubuntu2+esm1, 1:0.5.49-1ubuntu0.1
suricata - addressed in versions 7.0.11-1.el8, 7.0.11-1.el9, 7.0.11-1.fc41, 7.0.11-1.fc42
External References
Related Security Bulletins
- Denial of service in libhtp
- Fedora EPEL 9 update for suricata
- Fedora EPEL 9 update for suricata
- Fedora EPEL 8 update for suricata
- Fedora EPEL 8 update for suricata
- Fedora 41 update for suricata
- Fedora 41 update for suricata
- Fedora 42 update for suricata
- Fedora 42 update for suricata
- Ubuntu update for libhtp