Описание
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
A flaw was found in PCRE2. The pcre2_serialize_encode function might disclose two bytes of information to an attacker. This vulnerability typically occurs in scenarios where the attacker already has unsafe access to the system, making exploitation difficult. The primary impact is a limited information disclosure.
Отчет
This is a information disclosure flaw in PCRE2. The vulnerability, which could expose two bytes of data, requires an adversary to have already gained unsafe access to the system, significantly limiting its exploitability in typical Red Hat deployments.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | bootc | Not affected | ||
| Red Hat Enterprise Linux 10 | mariadb10.11 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | mariadb11.8 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | mingw-pcre2 | Not affected | ||
| Red Hat Enterprise Linux 10 | pcre2 | Not affected | ||
| Red Hat Enterprise Linux 7 | pcre2 | Not affected | ||
| Red Hat Enterprise Linux 8 | mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 8 | pcre2 | Not affected | ||
| Red Hat Enterprise Linux 9 | bootc | Not affected | ||
| Red Hat Enterprise Linux 9 | mariadb | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
2.9 Low
CVSS3
Связанные уязвимости
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes ...
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
EPSS
2.9 Low
CVSS3