Related Vulnerabilities: CVE-2018-20796  

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.

Severity Medium

Remote No

Type Denial of service

Description

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.

AVG-855 glibc 2.28-5 High Vulnerable

https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html
https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141