We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-29918

Suricata pcre: negated pcr can cause infinite loop



Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an infinite loop when negated PCRE is used. Packet processing thread becomes stuck in infinite loop limiting visibility and availability in inline mode. This vulnerability is fixed in 7.0.9.

Reserved 2025-03-12 | Published 2025-04-10 | Updated 2025-04-11 | Assigner GitHub_M


MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')

Product status

< 7.0.9
affected

References

github.com/...ricata/security/advisories/GHSA-924c-vvm5-9mqx

github.com/...ommit/b14c67cbdf25fa6c7ffe0d04ddf3ebe67b12b50b

redmine.openinfosecfoundation.org/issues/7526

cve.org (CVE-2025-29918)

nvd.nist.gov (CVE-2025-29918)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-29918

Support options

Helpdesk Chat, Email, Knowledgebase