Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Fedora 35: 2022-a3edad0ab6 Critical: Out-of-bounds Fix in pcre2

fedora
Calendar Grey May 25, 2022
Dist Fedora Esm H88
Enhance pcre2 to version 10.40 within Fedora to address security enhancements and rectify significant vulnerabilities.
Rebase to version 10.40

Summary

PCRE2 is a re-working of the original PCRE (Perl-compatible regular

expression) library to provide an entirely new API.

PCRE2 is written in C, and it has its own API. There are three sets of

functions, one for the 8-bit library, which processes strings of bytes, one

for the 16-bit library, which processes strings of 16-bit values, and one for

the 32-bit library, which processes strings of 32-bit values. There are no C++

wrappers. This package provides support for strings in 8-bit and UTF-8

encodings. Install pcre2-utf16 or pcre2-utf32 packages for the other ones.

The distribution does contain a set of C wrapper functions for the 8-bit

library that are based on the POSIX regular expression API (see the pcre2posix

man page). These can be found in a library called libpcre2posix. Note that

this just provides a POSIX calling interface to PCRE2; the regular expressions

themselves still follow Perl syntax and semantics. The POSIX API is

restricted, and does not give full access to all of PCRE2's facilities.

Rebase to version 10.40

* Mon Apr 25 2022 Lukas Javorsky - 10.40-1

- Rebase to the 10.40

- Resolves multiple Out-of-bounds read errors

[ 1 ] Bug #2075955 - pcre2-10.40 is available

https://bugzilla.redhat.com/show_bug.cgi?id=2075955

[ 2 ] Bug #2077986 - CVE-2022-1587 pcre2: Out-of-bounds read in get_recurse_data_length in pcre2_jit_compile.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2077986

[ 3 ] Bug #2077987 - CVE-2022-1586 pcre2: Out-of-bounds read in compile_xclass_matchingpath in pcre2_jit_compile.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2077987

su -c 'dnf upgrade --advisory FEDORA-2022-a3edad0ab6' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 35
Version: 10.40
Release: 1.fc35
URL: /
Summary: Perl-compatible regular expression library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here