ZeroHour

CVE-2022-1586

CVSS 3.1
9.1 critical
EPSS
3%p88
Published
()
Modified
Description

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.

Vendors
pcrefedoraprojectredhatnetappdebian
Products
pcre2, fedora, enterprise linux, active iq unified manager, hci management node, ontap select deploy administration utility, solidfire, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.