CVE-2022-23901

NameCVE-2022-23901
DescriptionA stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
re2c (PTS)jessie0.13.5-1vulnerable
stretch0.16-2vulnerable
buster1.1.1-1vulnerable
bullseye2.0.3-1vulnerable
bookworm3.0-2fixed
trixie, sid3.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
re2csource(unstable)3.0-1unimportant

Notes

https://github.com/skvadrik/re2c/issues/394
https://github.com/skvadrik/re2c/commit/a3473fd7be829cb33907cb08612f955133c70a96 (3.0)
https://github.com/skvadrik/re2c/commit/039c18949190c5de5397eba504d2c75dad2ea9ca (3.0)
Crash im CLI tool, no security impact
[stretch] - re2c <no-dsa> (Minor issue)
[jessie] - re2c <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems