Re: [LFS Trac] #5790: pcre2-10.46

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5790: pcre2-10.46
-------------------------+-----------------------
 Reporter:  Bruce Dubbs  |       Owner:  lfs-book
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  12.5
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Comment (by Bruce Dubbs):

 Version 10.46 27-August-2025

 This is a security-only release, to address CVE-2025-58050.

 Compared to 10.45, this release has only a minimal code change to prevent
 a
 read-past-the-end memory error, of arbitrary length. An attacker-
 controlled
 regex pattern is required, and it cannot be triggered by providing crafted
 subject (match) text. The (*ACCEPT) and (*scs:) pattern features must be
 used
 together.

 Release 10.44 and earlier are not affected.

 This could have implications of denial-of-service or information
 disclosure,
 and could potentially be used to escalate other vulnerabilities in a
 system
 (such as information disclosure being used to escalate the severity of an
 unrelated bug in another system).
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5790#comment:1>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.