9.1
CVSSv3

CVE-2022-1587

Published: 16/05/2022 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

An out-of-bounds read vulnerability exists in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pcre pcre2

redhat enterprise linux 9.0

fedoraproject fedora 35

fedoraproject fedora 36

netapp ontap select deploy administration utility -

netapp solidfire -

netapp hci management node -

netapp active iq unified manager -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h410s_firmware -

netapp h410c_firmware -

Vendor Advisories

Debian Bug report logs - #1011954 CVE-2022-1586 CVE-2022-1587 Package: src:pcre2; Maintainer for src:pcre2 is Matthew Vernon <matthew@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 27 May 2022 17:27:01 UTC Severity: important Tags: security Found in version pcre2/1036-2 Fixed in version pc ...
Synopsis Important: Red Hat OpenShift Data Foundation 4130 security and bug fix update Type/Severity Security Advisory: Important Topic Updated images that include numerous enhancements, security, and bug fixes are now available in Red Hat Container Registry for Red Hat OpenShift Data Foundation 4130 on Red Hat Enterprise Linux 9Red Hat ...
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compilec file This involves a unicode property matching issue in JIT-compiled regular expressions The issue occurs because the character was not fully read in case-less matching within JIT (CVE-2022-1586) An ou ...
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compilec file This involves a unicode property matching issue in JIT-compiled regular expressions The issue occurs because the character was not fully read in case-less matching within JIT (CVE-2022-1586) An ou ...