Re: [LFS Trac] #5790: pcre2-10.46
| Newsgroups | gmane.linux.lfs.book |
|---|---|
| Message-ID | <[email protected]> |
#5790: pcre2-10.46
-------------------------+-----------------------
Reporter: Bruce Dubbs | Owner: lfs-book
Type: enhancement | Status: new
Priority: normal | Milestone: 12.5
Component: Book | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-----------------------
Comment (by Bruce Dubbs):
Version 10.46 27-August-2025
This is a security-only release, to address CVE-2025-58050.
Compared to 10.45, this release has only a minimal code change to prevent
a
read-past-the-end memory error, of arbitrary length. An attacker-
controlled
regex pattern is required, and it cannot be triggered by providing crafted
subject (match) text. The (*ACCEPT) and (*scs:) pattern features must be
used
together.
Release 10.44 and earlier are not affected.
This could have implications of denial-of-service or information
disclosure,
and could potentially be used to escalate other vulnerabilities in a
system
(such as information disclosure being used to escalate the severity of an
unrelated bug in another system).
--
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5790#comment:1>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.
--
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page