Skip to content
This repository has been archived by the owner on Feb 23, 2024. It is now read-only.

Update pcre2 to 10.36-r1 #148

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

atomist[bot]
Copy link
Contributor

@atomist atomist bot commented Jun 23, 2022

This pull request updates package pcre2 from version 10.36-r0 to 10.36-r1 in order to fix vulnerability CVE-2022-1587.


CVE-2022-1587

Severity CRITICAL - CVSS 9.1

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.


File changed:

 [atomist:generated]
 [atomist-skill:atomist/docker-vulnerability-policy]

Signed-off-by: Atomist Bot <[email protected]>
@atomist atomist bot added auto-merge-method:merge Auto-merge with merge commit auto-merge:on-approve Auto-merge on review approvals auto-branch-delete:on-close Delete branch when pull request gets closed labels Jun 23, 2022
@atomist
Copy link
Contributor Author

atomist bot commented Jun 23, 2022

Vulnerabilities
Comparison

🚨 Adds 1 critical and 5 high severity vulnerabilities compared with unstable

💡 Rebase branch atomist/fix-cve-2022-1587/docker/dockerfile to include latest changes from branch main to increase accuracy of vulnerability report


More details are available in the vulnerability report

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge:on-approve Auto-merge on review approvals auto-merge-method:merge Auto-merge with merge commit
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant