CVE-2022-1587

CRITICAL

Pcre2 < 10.40 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

Scores

CVSS v3 9.1
EPSS 0.0025
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (13)
fedoraproject/fedora 35
fedoraproject/fedora 36
netapp/active_iq_unified_manager
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
netapp/hci_management_node
netapp/ontap_select_deploy_administration_utility
... and 3 more
Published May 16, 2022
Tracked Since Feb 18, 2026