Описание
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
A flaw was found in PCRE2. An out-of-bounds write vulnerability exists in the pcre2_dfa_match function due to improper size checking when reusing cached workspace blocks. A remote attacker could exploit this by providing a specially crafted regular expression or a recursive pattern in conjunction with a small heap limit. This could lead to data corruption or potentially arbitrary code execution, compromising the integrity and availability of the system.
Отчет
Important: An out-of-bounds write vulnerability in the PCRE2 library, specifically within the pcre2_dfa_match function, could allow arbitrary code execution. This flaw is exploitable in Red Hat products when processing attacker-controlled regular expressions or when a recursive pattern is used in conjunction with a small, API-set heap limit, making it dependent on specific application usage patterns.
Меры по смягчению последствий
To mitigate this Improper Protection of Alternate Path vulnerability, ensure that secondary execution branches—such as the reuse of cached memory workspaces—enforce the exact same size and boundary checks as the primary memory allocation paths. Limit exposure by preventing untrusted user input from directly controlling PCRE2 regular expressions, and strictly avoid utilizing recursive matching patterns when operating under a low heap limit. Apply a defense-in-depth strategy by validating all inputs comprehensively.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | bootc | Not affected | ||
| Red Hat Enterprise Linux 10 | mariadb10.11 | Affected | ||
| Red Hat Enterprise Linux 10 | mariadb11.8 | Affected | ||
| Red Hat Enterprise Linux 10 | mingw-pcre2 | Affected | ||
| Red Hat Enterprise Linux 10 | pcre2 | Affected | ||
| Red Hat Enterprise Linux 7 | pcre2 | Not affected | ||
| Red Hat Enterprise Linux 8 | mariadb:10.11/mariadb | Affected | ||
| Red Hat Enterprise Linux 8 | pcre2 | Affected | ||
| Red Hat Enterprise Linux 9 | bootc | Not affected | ||
| Red Hat Enterprise Linux 9 | mariadb:10.11/mariadb | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
(PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...)
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
EPSS
8.2 High
CVSS3