Lucene search

K
osvGoogleOSV:RLSA-2022:5251
HistoryJun 28, 2022 - 8:27 a.m.

Moderate: pcre2 security update

2022-06-2808:27:30
Google
osv.dev
4

9.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.1%

The pcre2 package contains a new generation of the Perl Compatible Regular Expression libraries for implementing regular expression pattern matching using the same syntax and semantics as Perl.

Security Fix(es):

  • pcre2: Out-of-bounds read in compile_xclass_matchingpath in pcre2_jit_compile.c (CVE-2022-1586)

  • pcre2: Out-of-bounds read in get_recurse_data_length in pcre2_jit_compile.c (CVE-2022-1587)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.