CVE-2022-41409

NameCVE-2022-41409
DescriptionInteger overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pcre2 (PTS)buster10.32-5vulnerable
buster (security)10.32-5+deb10u1vulnerable
bullseye10.36-2+deb11u1vulnerable
bookworm10.42-1fixed
trixie, sid10.42-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pcre2source(unstable)10.42-1unimportant

Notes

https://github.com/PCRE2Project/pcre2/issues/141
https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35
Infinite loop in CLI tool, no security impact

Search for package or bug name: Reporting problems