Out-of-Bounds Read Vulnerability in PCRE2 Library
CVE-2022-1586
9.1CRITICAL
What is CVE-2022-1586?
An out-of-bounds read vulnerability has been identified in the PCRE2 library, specifically within the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This flaw arises from an issue with unicode property matching in JIT-compiled regular expressions, where a character may not be fully read during case-less matching. Exploitation of this vulnerability could lead to unexpected behavior in applications utilizing the library, thereby compromising the integrity of the data processed.
Affected Version(s)
pcre2 Fixed in pcre2-10.40.
