RHSA-2021:4373LowCVSS 7.5
Red Hat Security Advisory: pcre security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2019-20838 — pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1 CVE-2020-14155 — pcre: Integer overflow when parsing callout numeric arguments
🎯 Affected products93
- Red Hat CodeReady Linux Builder (v. 8)
- Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-0:8.42-6.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-0:8.42-6.el8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-0:8.42-6.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-0:8.42-6.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-0:8.42-6.el8.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-0:8.42-6.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-0:8.42-6.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-0:8.42-6.el8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-0:8.42-6.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-0:8.42-6.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-0:8.42-6.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.i686 as a component of Red Hat CodeReady Linux Builder (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.s390x as a component of Red Hat CodeReady Linux Builder (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 8)
- pcre-cpp-debuginfo-0:8.42-6.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-debuginfo-0:8.42-6.el8.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 8)
- pcre-debuginfo-0:8.42-6.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-debuginfo-0:8.42-6.el8.i686 as a component of Red Hat CodeReady Linux Builder (v. 8)
- pcre-debuginfo-0:8.42-6.el8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-debuginfo-0:8.42-6.el8.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 8)
- pcre-debuginfo-0:8.42-6.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- pcre-debuginfo-0:8.42-6.el8.s390x as a component of Red Hat CodeReady Linux Builder (v. 8)
- +63 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Do not use more than one fixed quantifier with \R or \X with UTF disabled in PCRE or PCRE2, as these are the conditions needed to trigger the flaw. Workaround: This flaw can be mitigated by not compiling regular expressions with a callout value greater outside of 0-255 or handling the value passed to the callback within the application code.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2021:4373
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848436
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848444
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4373.json