Infinite Loop Vulnerability in Suricata Network Security Monitoring Engine
CVE-2025-29918

6.2MEDIUM

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
10 April 2025

What is CVE-2025-29918?

Suricata, a widely used network intrusion detection and prevention system, has a vulnerability that can result in an infinite loop during packet processing. This occurs specifically when negated PCRE (Perl Compatible Regular Expressions) rules are utilized in certain conditions, causing the processing thread to become unresponsive. As a result, visibility and availability are significantly hindered, particularly in inline mode. This critical issue underscores the importance of updating Suricata to version 7.0.9 or later, where the vulnerability has been addressed.

Affected Version(s)

suricata < 7.0.9

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.