Out-of-bounds read in PCRE2 - CVE-2022-1586

 

Out-of-bounds read in PCRE2 - CVE-2022-1586

Published: June 2, 2022


Vulnerability identifier: #VU63945
CSH Severity: Medium
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1586
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a boundary condition in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. A remote attacker can pass specially crafted data to the application, trigger out-of-bounds read error, gain access to sensitive information or perform a denial of service attack.


Affected software

PCRE2
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Oracle Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Ubuntu
Fedora
Submariner
Gatekeeper Operator
Data Lakehouse
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Netcool Operations Insight
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Aspera Orchestrator
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack
IBM Robotic Process Automation
Self Node Remediation Operator
OpenShift sandboxed containers
Multicluster Engine for Kubernetes
OpenShift Service Mesh
Node Maintenance Operator
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Dell EMC NetWorker vProxy
Red Hat Ceph Storage
SecurID Authentication Manager
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pcre2 (Red Hat package)
libpcre1
libpcre1-32bit
pcre-tools-debuginfo
pcre-tools
pcre-devel-static
libpcrecpp0-debuginfo-32bit
libpcrecpp0-32bit
pcre-devel
pcre-debugsource
libpcreposix0-debuginfo
libpcreposix0
libpcrecpp0-debuginfo
libpcrecpp0
libpcre16-0-debuginfo
libpcre16-0
libpcre1-debuginfo
libpcre1-debuginfo-32bit
libpcre16-0-32bit-debuginfo
libpcrecpp0-32bit-debuginfo
libpcreposix0-32bit
libpcreposix0-32bit-debuginfo
pcre-doc
libpcre16-0-32bit
libpcre1-32bit-debuginfo
libpcre2-16-0
libpcre2-posix2
libpcre2-16-0-debuginfo
libpcre2-32-0
libpcre2-32-0-debuginfo
libpcre2-8-0
libpcre2-8-0-debuginfo
libpcre2-posix2-debuginfo
pcre2-debugsource
pcre2-devel
pcre2-devel-static
pcre2-tools
pcre2-tools-debuginfo
libpcre2-16-0-32bit
libpcre2-16-0-32bit-debuginfo
libpcre2-32-0-32bit
libpcre2-32-0-32bit-debuginfo
libpcre2-8-0-32bit
libpcre2-8-0-32bit-debuginfo
libpcre2-posix2-32bit
libpcre2-posix2-32bit-debuginfo
pcre2-doc
pcre2-utf16
pcre2-utf32
pcre2
libpcre2-posix2 (Ubuntu package)
libpcre2-8-0 (Ubuntu package)
libpcre2-16-0 (Ubuntu package)
pcre2-utils (Ubuntu package)
libpcre2-32-0 (Ubuntu package)
pcre2-help
pcre2-debuginfo
libpcre2-posix3 (Ubuntu package)
mingw-pcre2
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
IBM Aspera Shares
PowerStore X
PowerStore T
IBM Aspera Console
EMC ECS
IBM Cloud Pak for Watson AIOps
Dell Data Protection Central
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC VxRail Appliance

How to mitigate CVE-2022-1586

Install updates from vendor's website.

PCRE2 - update to 10.40
Submariner - update to 0.13.0
Gatekeeper Operator - update to 0.2
Self Node Remediation Operator - update to 0.4.1
OpenShift sandboxed containers - update to 1.3.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.4, 1.1.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
Data Lakehouse - update to 1.1.0.0
IBM MQ Operator - addressed in versions 1.3.7, 2.0.2
Migration Toolkit for Containers - update to 1.7.4
Multicluster Engine for Kubernetes - addressed in versions 2.0.2, 2.1
OpenShift Service Mesh - update to 2.2.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.12, 2.4.6, 2.5.2, 2.6.0
Red Hat Advanced Cluster Security for Kubernetes - update to 3.72
Dell EMC NetWorker vProxy - addressed in versions 4.3.0-31, 4.3.0-32
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.1, 4.11.45, 4.13.0
Node Maintenance Operator - update to 4.11.1
OpenShift Logging - addressed in versions 5.3.11, 5.3.14, 5.4.5, 5.5.5
SecurID Authentication Manager - addressed in versions 8.6 Patch 4, 8.7 Patch 1
pcre2 (Red Hat package) - addressed in versions 10.32-3.el8_6, 10.37-5.el9_0
Netcool Operations Insight - update to 1.6.7
IBM Aspera Shares - update to 1.10.0 PL4
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
PowerStore X - update to 3.2.1.0-1989710
PowerStore T - update to 3.2.1.0-1989710
IBM Aspera Console - update to 3.4.2 PL 10
EMC ECS - update to 3.7.0.3
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.11.0, 4.13.0
OpenShift Virtualization - addressed in versions 4.11.1, 4.12.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.1.0.5.013
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.1.0.5.013
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.1.0.5.013
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 8, 7.5.0 Update Pack 4
Dell EMC VxRail Appliance - update to 8.0.000
libpcre1 - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcre1-32bit - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
pcre-tools-debuginfo - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
pcre-tools - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
pcre-devel-static - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcrecpp0-debuginfo-32bit - update to 8.45-8.12.1
libpcrecpp0-32bit - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
pcre-devel - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
pcre-debugsource - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcreposix0-debuginfo - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcreposix0 - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcrecpp0-debuginfo - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcrecpp0 - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcre16-0-debuginfo - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcre16-0 - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcre1-debuginfo - addressed in versions 8.45-8.12.1, 8.45-150000.20.13.1
libpcre1-debuginfo-32bit - update to 8.45-8.12.1
libpcre16-0-32bit-debuginfo - update to 8.45-150000.20.13.1
libpcrecpp0-32bit-debuginfo - update to 8.45-150000.20.13.1
libpcreposix0-32bit - update to 8.45-150000.20.13.1
libpcreposix0-32bit-debuginfo - update to 8.45-150000.20.13.1
pcre-doc - update to 8.45-150000.20.13.1
libpcre16-0-32bit - update to 8.45-150000.20.13.1
libpcre1-32bit-debuginfo - update to 8.45-150000.20.13.1
libpcre2-16-0 - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
libpcre2-posix2 - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
libpcre2-16-0-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
libpcre2-32-0 - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
libpcre2-32-0-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
libpcre2-8-0 - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
libpcre2-8-0-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
libpcre2-posix2-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
pcre2-debugsource - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
pcre2-devel - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
pcre2-devel-static - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
pcre2-tools - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
pcre2-tools-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.34-1.7.1, 10.39-150400.4.3.1
libpcre2-16-0-32bit - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
libpcre2-16-0-32bit-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
libpcre2-32-0-32bit - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
libpcre2-32-0-32bit-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
libpcre2-8-0-32bit - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
libpcre2-8-0-32bit-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
libpcre2-posix2-32bit - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
libpcre2-posix2-32bit-debuginfo - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
pcre2-doc - addressed in versions 10.31-150000.3.7.1, 10.39-150400.4.3.1
pcre2-devel - update to 10.32-3.0.1
pcre2-tools - update to 10.32-3.0.1
pcre2-utf16 - update to 10.32-3.0.1
pcre2-utf32 - update to 10.32-3.0.1
pcre2 - update to 10.32-3.0.1
libpcre2-posix2 (Ubuntu package) - update to 10.34-7ubuntu0.1
libpcre2-8-0 (Ubuntu package) - addressed in versions 10.34-7ubuntu0.1, 10.39-3ubuntu0.1
libpcre2-16-0 (Ubuntu package) - addressed in versions 10.34-7ubuntu0.1, 10.39-3ubuntu0.1
pcre2-utils (Ubuntu package) - addressed in versions 10.34-7ubuntu0.1, 10.39-3ubuntu0.1
libpcre2-32-0 (Ubuntu package) - addressed in versions 10.34-7ubuntu0.1, 10.39-3ubuntu0.1
pcre2-help - update to 10.35-2
pcre2-debuginfo - update to 10.35-2
pcre2-debugsource - update to 10.35-2
pcre2-devel - update to 10.35-2
pcre2 - update to 10.35-2
libpcre2-posix3 (Ubuntu package) - update to 10.39-3ubuntu0.1
pcre2 - update to 10.40-1
mingw-pcre2 - addressed in versions 10.40-1.fc35, 10.40-1.fc36
pcre2 - addressed in versions 10.40-1.fc35, 10.40-1.fc36
Red Hat OpenStack - update to 16.2.z
Dell Data Protection Central - update to 19.7.0-9
IBM Robotic Process Automation - update to 21.0.5

External References

Related Security Bulletins