CVE-2022-3517

NameCVE-2022-3517
DescriptionA vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3271-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-minimatch (PTS)jessie1.0.0-1vulnerable
stretch3.0.3-1vulnerable
buster (security), buster, buster (lts)3.0.4-3+deb10u1fixed
bullseye3.0.4+~3.0.3-1+deb11u2fixed
bookworm5.1.1+~5.1.2-1fixed
sid, trixie9.0.3-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-minimatchsourcejessie(unfixed)end-of-life
node-minimatchsourcestretch(unfixed)end-of-life
node-minimatchsourcebuster3.0.4-3+deb10u1DLA-3271-1
node-minimatchsourcebullseye3.0.4+~3.0.3-1+deb11u1
node-minimatchsource(unstable)3.0.5+~3.0.5-1

Notes

https://github.com/grafana/grafana-image-renderer/issues/329
https://github.com/isaacs/minimatch/commit/a8763f4388e51956be62dc6025cec1126beeb5e6 (v3.0.5)
Regression follow-up: https://github.com/isaacs/minimatch/commit/20b4b562830680867feb75f9c635aca08e5c86ff
Regression follow-up: https://github.com/isaacs/minimatch/commit/e4cd43462340ca6b21212b68c9e314d8cdd9861a

Search for package or bug name: Reporting problems