CVE-2022-1587Out-of-bounds Read in Pcre2

CWE-125Out-of-bounds Read13 documents10 sources
Severity
9.1CRITICALNVD
EPSS
0.3%
top 51.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateApr 15

Description

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

NVDpcre/pcre2< 10.40
Debianpcre/pcre2< 10.36-2+deb11u1+3
CVEListV5pcre/pcre2Fixed in pcre2-10.40.

Also affects: Fedora 35, 36, Enterprise Linux 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jmvm-hj36-w5hc: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile2022-05-17
CVEList
CVE-2022-1587: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile2022-05-16
OSV
CVE-2022-1587: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile2022-05-16

📋Vendor Advisories

7
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (PCRE2) — CVE-2022-15872023-04-15
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Notification Server (PCRE2) — CVE-2022-15872022-10-15
Ubuntu
PCRE vulnerabilities2022-09-22
Ubuntu
PCRE vulnerabilities2022-09-22
Microsoft
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular2022-05-10

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution2022-10-11
Talos
Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution2022-10-11
CVE-2022-1587 — Out-of-bounds Read in Pcre Pcre2 | cvebase