CVE-2022-1587
published 2022-05-16CVE-2022-1587: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue…
critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre2 | < pcre2 10.40-1 (bookworm) | pcre2 10.40-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cm1_pcre2_10.34-2_on_cbl_mariner_1.0 | — | — |
| pcre | pcre2 | < 10.40 | 10.40 |
| pcre | pcre2 | — | — |
| pcre | pcre2 | >= 0 < 10.36-2+deb11u1 | 10.36-2+deb11u1 |
| pcre | pcre2 | >= 0 < 10.40-1 | 10.40-1 |
| pcre | pcre2 | >= 0 < 10.40-1 | 10.40-1 |
| pcre | pcre2 | >= 0 < 10.40-1 | 10.40-1 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (PCRE2) — CVE-2022-1587
vendor_oracle·2023-04-15·CVSS 9.1
CVE-2022-1587 [CRITICAL] Oracle Oracle Analytics Risk Matrix: Analytics Server (PCRE2) — CVE-2022-1587
Oracle Oracle Analytics Risk Matrix: Analytics Server (PCRE2) vulnerability
CVE: CVE-2022-1587
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Notification Server (PCRE2) — CVE-2022-1587
vendor_oracle·2022-10-15·CVSS 6.5
CVE-2022-1587 [CRITICAL] Oracle Oracle Database Server Risk Matrix: Oracle Notification Server (PCRE2) — CVE-2022-1587
Oracle Oracle Database Server Risk Matrix: Oracle Notification Server (PCRE2) vulnerability
CVE: CVE-2022-1587
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2022-09-22
CVE-2022-1586 PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to expose sensitive information.
It was discovered that PCRE incorrectly handled memory when
handling certain regular expressions. An attacker could possibly
use this issue to cause applications using PCRE to expose
sensitive information.
Instructions: After a standard system update you need to restart applications using PCRE,
such as the Apache HTTP server and Nginx, to make all the necessary
changes.
Ubuntu
PCRE vulnerabilities
vendor_ubuntu·2022-09-22
CVE-2022-1586 PCRE vulnerabilities
Title: PCRE vulnerabilities
Summary: PCRE could be made to expose sensitive information.
USN-5627-1 fixed several vulnerabilities in PCRE. This update
provides the corresponding fixes for Ubuntu 18.04 ESM.
Original advisory details:
It was discovered that PCRE incorrectly handled memory when
handling certain regular expressions. An attacker could possibly
use this issue to cause applications using PCRE to expose
sensitive information.
Instructions: After a standard system update you need to restart applications using PCRE,
such as the Apache HTTP server and Nginx, to make all the necessary
changes.
Microsoft
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular
vendor_msrc·2022-05-10·CVSS 9.1
CVE-2022-1587 [CRITICAL] CWE-125 An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to addit
Red Hat
pcre2: Out-of-bounds read in get_recurse_data_length in pcre2_jit_compile.c
vendor_redhat·2022-03-26·CVSS 9.1
CVE-2022-1587 [CRITICAL] CWE-125 pcre2: Out-of-bounds read in get_recurse_data_length in pcre2_jit_compile.c
pcre2: Out-of-bounds read in get_recurse_data_length in pcre2_jit_compile.c
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
Package: pcre2 (Red Hat Enterprise Linux 7) - Not affected
Package: pcre2 (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2022-1587: pcre2 - An out-of-bounds read vulnerability was discovered in the PCRE2 library in the g...
vendor_debian·2022·CVSS 9.1
CVE-2022-1587 [CRITICAL] CVE-2022-1587: pcre2 - An out-of-bounds read vulnerability was discovered in the PCRE2 library in the g...
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
Scope: local
bookworm: resolved (fixed in 10.40-1)
bullseye: resolved (fixed in 10.36-2+deb11u1)
forky: resolved (fixed in 10.40-1)
sid: resolved (fixed in 10.40-1)
trixie: resolved (fixed in 10.40-1)
GHSA
GHSA-jmvm-hj36-w5hc: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile
ghsa_unreviewed·2022-05-17
CVE-2022-1587 [CRITICAL] CWE-125 GHSA-jmvm-hj36-w5hc: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
OSV
CVE-2022-1587: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile
osv·2022-05-16·CVSS 9.1
CVE-2022-1587 [CRITICAL] CVE-2022-1587: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
blogs_talos·2022-10-11·CVSS 9.1
[CRITICAL] Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable data deserialization vulnerability in the VMware vCenter server platform.
VMware is one of the most popular virtual machine solutions currently available, and its vCenter software allows users to manage an entire environment of VMs. The vulnerability Talos discovered is a post-authentication Java deserialization issue that could corrupt the software in a way that could allow an attacker to exploit arbitrary code on the target machine.
TALOS-2022-1587 (CVE-2022-31680) is triggered if an adversary sends a specially crafted HTTP request to a targeted machine. The attacker would first have to log in with legitimate credentials to vCenter to be successful.
Cisco Talos worked wi
Talos
Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
blogs_talos·2022-10-11·CVSS 9.1
[CRITICAL] Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
## Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable data deserialization vulnerability in the VMware vCenter server platform.
VMware is one of the most popular virtual machine solutions currently available, and its vCenter software allows users to manage an entire environment of VMs. The vulnerability Talos discovered is a post-authentication Java deserialization issue that could corrupt the software in a way that could allow an attacker to exploit arbitrary code on the target machine.
TALOS-2022-1587 (CVE-2022-31680) is triggered if an adversary sends a specially crafted HTTP request to a targeted machine. The attacker wo
https://bugzilla.redhat.com/show_bug.cgi?id=2077983%2Chttps://github.com/PCRE2Project/pcre2/commit/03654e751e7f0700693526b67dfcadda6b42c9d0https://lists.debian.org/debian-lts-announce/2023/03/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWNG2NS3GINO6LQYUVC4BZLUQPJ3DYHA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXINO3KKI5DICQ45E2FKD6MKVMGJLEKJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KAX7767BCUFC7JMDGP7GOQ5GIZCAUGBB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2GLQQUEY5VFM57CFYXVIFOXN2HUZPDM/https://security.netapp.com/advisory/ntap-20221028-0009/https://bugzilla.redhat.com/show_bug.cgi?id=2077983%2Chttps://github.com/PCRE2Project/pcre2/commit/03654e751e7f0700693526b67dfcadda6b42c9d0https://lists.debian.org/debian-lts-announce/2023/03/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWNG2NS3GINO6LQYUVC4BZLUQPJ3DYHA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXINO3KKI5DICQ45E2FKD6MKVMGJLEKJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KAX7767BCUFC7JMDGP7GOQ5GIZCAUGBB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2GLQQUEY5VFM57CFYXVIFOXN2HUZPDM/https://security.netapp.com/advisory/ntap-20221028-0009/
2022-05-16
Published