CVE-2019-20454
published 2020-02-14CVE-2019-20454: An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.56%
72.5th percentile
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 11.0.1 | 11.0.1 |
| debian | pcre2 | < pcre2 10.34-1 (bookworm) | pcre2 10.34-1 (bookworm) |
| debian | pcre3 | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_pcre_8.44-1_on_cbl_mariner_1.0 | — | — |
| pcre | pcre | < 8.43 | 8.43 |
| pcre | pcre2 | >= 0 < 10.34-1 | 10.34-1 |
| pcre | pcre2 | >= 0 < 10.34-1 | 10.34-1 |
| pcre | pcre2 | >= 0 < 10.34-1 | 10.34-1 |
| pcre | pcre2 | >= 0 < 10.34-1 | 10.34-1 |
| pcre | pcre2 | >= 10.31 < 10.34 | 10.34 |
| splunk | universal_forwarder | — | — |
| splunk | universal_forwarder | >= 8.2.0 < 8.2.12 | 8.2.12 |
| splunk | universal_forwarder | >= 9.0.0 < 9.0.6 | 9.0.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1
vendor_redhat·2020-06-15·CVSS 7.5
CVE-2019-20838 [HIGH] CWE-125 pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1
pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
Mitigation: Do not use more than one fixed quantifier with \R or \X with UTF disabled in PCRE or PCRE2, as these are the conditions needed to trigger the flaw.
Package: rhacm2/management-ingress-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Fix deferred
Package: pcre (Red Hat Enterprise Linux 6) - Not affected
Package: pcre (Red Hat Enterprise Linux 7) - Not affected
Microsoft
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled and \X or \R has more than one fixed quantifier a related issue to CVE-2019-20454.
vendor_msrc·2020-06-09·CVSS 7.5
CVE-2019-20838 [HIGH] CWE-125 libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled and \X or \R has more than one fixed quantifier a related issue to CVE-2019-20454.
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled and \X or \R has more than one fixed quantifier a related issue to CVE-2019-20454.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Marin
Red Hat
pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode
vendor_redhat·2019-07-28·CVSS 7.5
CVE-2019-20454 [HIGH] CWE-125 pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode
pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.
An out-of-bounds read was discovered in PCRE when the pattern "\X" is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to crash the application.
Package: pcre (Red Hat Enterprise Linux 5) - Out of support scope
Package: chromiu
Debian
CVE-2019-20838: pcre3 - libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is...
vendor_debian·2019·CVSS 7.5
CVE-2019-20838 [HIGH] CVE-2019-20838: pcre3 - libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is...
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
Scope: local
bookworm: open
bullseye: open
Debian
CVE-2019-20454: pcre2 - An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is...
vendor_debian·2019·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454: pcre2 - An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is...
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.
Scope: local
bookworm: resolved (fixed in 10.34-1)
bullseye: resolved (fixed in 10.34-1)
forky: resolved (fixed in 10.34-1)
sid: resolved (fixed in 10.34-1)
trixie: resolved (fixed in 10.34-1)
GHSA
GHSA-689f-qv4w-xgqf: libpcre in PCRE before 8
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-20838 [HIGH] CWE-125 GHSA-689f-qv4w-xgqf: libpcre in PCRE before 8
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
GHSA
GHSA-6wcm-vmc4-h93p: An out-of-bounds read was discovered in PCRE before 10
ghsa_unreviewed·2022-05-24
CVE-2019-20454 [MEDIUM] CWE-125 GHSA-6wcm-vmc4-h93p: An out-of-bounds read was discovered in PCRE before 10
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.
OSV
CVE-2019-20838: libpcre in PCRE before 8
osv·2020-06-15·CVSS 7.5
CVE-2019-20838 [HIGH] CVE-2019-20838: libpcre in PCRE before 8
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
OSV
CVE-2019-20454: An out-of-bounds read was discovered in PCRE before 10
osv·2020-02-14·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454: An out-of-bounds read was discovered in PCRE before 10
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20838 pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1
bugzilla·2020-06-18·CVSS 7.5
CVE-2019-20838 [HIGH] CVE-2019-20838 pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1
CVE-2019-20838 pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1
A vulnerability was found in libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
References:
https://bugs.gentoo.org/717920
https://www.pcre.org/original/changelog.txt
Discussion:
Created mingw-pcre tracking bugs for this issue:
Affects: fedora-all [bug 1848446]
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1848445]
---
Upstream fix .
---
The flaw is in the file pcre_jit_compile.c routine, compile_iterator_matchingpath(). The affected code is not in versions of pcre shipped with Red Hat Enterprise Linux 5, 6, or 7.
---
U
Bugzilla
CVE-2019-20454 pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
bugzilla·2020-02-14·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454 pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
CVE-2019-20454 pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2019-20454 mingw-glib2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
bugzilla·2020-02-14·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454 mingw-glib2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
CVE-2019-20454 mingw-glib2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-20454 pcre2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
bugzilla·2020-02-14·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454 pcre2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
CVE-2019-20454 pcre2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2019-20454 mingw-pcre: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
bugzilla·2020-02-14·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454 mingw-pcre: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
CVE-2019-20454 mingw-pcre: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2019-20454 mingw-pcre2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
bugzilla·2020-02-14·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454 mingw-pcre2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
CVE-2019-20454 mingw-pcre2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-20454 glib2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
bugzilla·2020-02-14·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454 glib2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
CVE-2019-20454 glib2: pcre: out-of-bounds read in JIT mode when \X is used in non-UTF mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2019-20454 pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode
bugzilla·2019-08-01·CVSS 7.5
CVE-2019-20454 [HIGH] CVE-2019-20454 pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode
CVE-2019-20454 pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode
A flaw was found in libpcre. A buffer overread in JIT mode when \X is used in non-UTF mode may cause application crash and denial of service. The flaw is in function do_extuni_no_utf() in pcre2_jit_compile.c, which uses the macro GETCHARINC to read a character. However, in case there is an invalid UTF character the value read is too big, which causes an out-of-bounds read in the next statement, while executing macro UCD_GRAPHBREAK.
References:
https://bugs.exim.org/show_bug.cgi?id=2421
https://bugzilla.redhat.com/show_bug.cgi?id=1734468
Upstream patch:
http://git.php.net/?p=php-src.git;a=commitdiff;h=8947fd9e9fdce87cd6c59817b1db58e789538fe9
Discussion:
(In reply to Pedro Sampaio from comment #0)
> Up
https://bugs.exim.org/show_bug.cgi?id=2421https://bugs.php.net/bug.php?id=78338https://bugzilla.redhat.com/show_bug.cgi?id=1735494https://lists.debian.org/debian-lts-announce/2023/03/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQRAHYHLRNMBTPR3KXVM27NSZP3KTOPI/https://security.gentoo.org/glsa/202006-16https://vcs.pcre.org/pcre2?view=revision&revision=1092https://bugs.exim.org/show_bug.cgi?id=2421https://bugs.php.net/bug.php?id=78338https://bugzilla.redhat.com/show_bug.cgi?id=1735494https://lists.debian.org/debian-lts-announce/2023/03/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQRAHYHLRNMBTPR3KXVM27NSZP3KTOPI/https://security.gentoo.org/glsa/202006-16https://vcs.pcre.org/pcre2?view=revision&revision=1092
2020-02-14
Published