CVE-2025-29918: Suricata pcre: negated pcr can cause infinite loop
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an infinite loop when negated PCRE is used. Packet processing thread becomes stuck in infinite loop limiting visibility and availability in inline mode. This vulnerability is fixed in 7.0.9.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29918?
CVE-2025-29918 is considered a high severity vulnerability due to its potential to cause Denial of Service through infinite loops in packet processing.
How do I fix CVE-2025-29918?
To fix CVE-2025-29918, upgrade Suricata to a version later than 7.0.9 where the vulnerability has been addressed.
What type of software is affected by CVE-2025-29918?
CVE-2025-29918 affects Suricata, a network Intrusion Detection System and Intrusion Prevention System.
What are the consequences of CVE-2025-29918?
The consequences of CVE-2025-29918 include packet processing threads becoming stuck, leading to limited visibility and potential Denial of Service.
Is CVE-2025-29918 present in older versions of Suricata?
Yes, CVE-2025-29918 is present in Suricata versions up to and including 7.0.9.