In the GNU C Library (aka glibc or libc6) through 2.29,...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Feb 26, 2019
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Jan 27, 2023
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
References