CVE-2019-20838 PUBLISHED

libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.

EPSS 0.31% · 53.6th percentile

Risk Scores

EPSS Score
0.31%
53.6th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10pcre30, 2:8.39-15.1
Ubuntu:20.04:LTSpcre32:8.39-12build1, 0, 2:8.39-12
Ubuntu:24.04:LTSpcre32:8.39-15, 0, 2:8.39-15build1
Ubuntu:22.04:LTSpcre32:8.39-13build5, 0, 2:8.39-13build3
Ubuntu:18.04:LTSpcre32:8.39-8, 0, 2:8.39-5ubuntu3

Timeline

References

Open in Interactive Console →