CVE-2022-1586Out-of-bounds Read in Pcre2

Severity
9.1CRITICALNVD
EPSS
0.6%
top 30.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateJan 10

Description

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

NVDpcre/pcre2< 10.40
Debianpcre/pcre2< 10.36-2+deb11u1+3
CVEListV5pcre/pcre2Fixed in pcre2-10.40.

Also affects: Debian Linux 10.0, Fedora 35, 36, Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f3pv-9fwh-mp3x: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile2022-05-17
CVEList
CVE-2022-1586: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile2022-05-16
OSV
CVE-2022-1586: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile2022-05-16

📋Vendor Advisories

7
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (PCRE2) — CVE-2022-15862022-10-15
Ubuntu
PCRE vulnerabilities2022-09-22
Ubuntu
PCRE vulnerabilities2022-09-22
Microsoft
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue i2022-05-10
Red Hat
pcre2: Out-of-bounds read in compile_xclass_matchingpath in pcre2_jit_compile.c2022-03-23

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Asus router access, information disclosure, denial of service vulnerabilities discovered2023-01-10
Talos
Vulnerability Spotlight: Asus router access, information disclosure, denial of service vulnerabilities discovered2023-01-10
CVE-2022-1586 — Out-of-bounds Read in Pcre Pcre2 | cvebase