Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-29918


Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an infinite loop when negated PCRE is used. Packet processing thread becomes stuck in infinite loop limiting visibility and availability in inline mode. This vulnerability is fixed in 7.0.9.


Published

2025-04-10T21:15:49.033

Last Modified

2025-05-29T15:49:18.377

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.2 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-835

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oisf suricata < 7.0.9 Yes

References