CVE-2022-23901

NameCVE-2022-23901
DescriptionA stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
re2c (PTS)stretch0.16-2vulnerable
buster1.1.1-1vulnerable
bullseye2.0.3-1vulnerable
bookworm, sid3.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
re2csource(unstable)3.0-1unimportant

Notes

https://github.com/skvadrik/re2c/issues/394
https://github.com/skvadrik/re2c/commit/a3473fd7be829cb33907cb08612f955133c70a96 (3.0)
https://github.com/skvadrik/re2c/commit/039c18949190c5de5397eba504d2c75dad2ea9ca (3.0)
Crash im CLI tool, no security impact

Search for package or bug name: Reporting problems