Out-of-Bounds Read Vulnerability in PCRE2 Library by Vendor
CVE-2022-1587

9.1CRITICAL

Key Information:

Vendor

Pcre

Status
Vendor
CVE Published:
16 May 2022

What is CVE-2022-1587?

An out-of-bounds read vulnerability was identified in the PCRE2 library, occurring specifically in the get_recurse_data_length() function within the pcre2_jit_compile.c file. This defect impacts the functionality of JIT-compiled regular expressions, primarily due to issues arising from duplicate data transfers, potentially leading to unintended data exposure or application instabilities.

Affected Version(s)

pcre2 Fixed in pcre2-10.40.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.