peter bassill · operator
$ cve CVE-2022-1586 JSON

CVE-2022-1586

9.1
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 88)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS3.37% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-125
On CISA KEVno
Public exploitnone known
Published2022-05-16
Last modified2026-06-17

Affected (18)

VendorProduct
debiandebian linux
fedoraprojectfedora
netappactive iq unified manager
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500s
netapph500s firmware
netapph700s
netapph700s firmware
netapphci management node
netappontap select deploy administration utility
netappsolidfire
pcrepcre2
redhatenterprise linux

References

→ the Explorer  ·  watch your stack  ·  NVD