CVE-2022-1586

Source
https://cve.org/CVERecord?id=CVE-2022-1586
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1586.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-1586
Downstream
ALPINE (1)
BELL (1)
CGA (2)
CLEANSTART (1)
CLSA (2)
DEBIAN (1)
MGASA (1)
OESA (1)
openSUSE (1)
RHSA (2)
RLSA (2)
SUSE (6)
UBUNTU (1)
Related
Published
2022-05-16T00:00:00Z
Modified
2026-08-12T12:59:11Z
Summary
[none]
Details

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-125"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1586.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "Fixed in pcre2-10.40."
                },
                {
                    "last_affected":  "Fixed in pcre2-10.40."
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/pcre2project/pcre2

Affected ranges

Type
GIT
Repo
https://github.com/pcre2project/pcre2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "10.40"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

pcre2-10.*
pcre2-10.38
pcre2-10.38-RC1
pcre2-10.39

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1586.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "41300829383723252943297909714980710868",
            "length":  19889
        },
        "id":  "CVE-2022-1586-2fd20eca",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/pcre2project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a",
        "target":  {
            "file":  "src/pcre2_jit_compile.c",
            "function":  "compile_xclass_matchingpath"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "339620945348427712212381388545774342412",
                "124167549058306645007988220067075173415",
                "309395507812416031802042378554291166529",
                "16059173172654235410661150339161003337"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-1586-486e13a2",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/pcre2project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a",
        "target":  {
            "file":  "src/pcre2_jit_test.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "136593279028409485865868554239388333420",
            "length":  2132
        },
        "id":  "CVE-2022-1586-8505e630",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/pcre2project/pcre2/commit/3103b8f20a3b9944b177e812fde29fbfb8b90558",
        "target":  {
            "file":  "src/pcre2test.c",
            "function":  "display_properties"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "261031969686312999006512549674494490461",
                "168259855099571918664674207254596473730",
                "129755615421991772175711125174276683242",
                "141477962428344099817664558993047106632"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-1586-b26c3441",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/pcre2project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a",
        "target":  {
            "file":  "src/pcre2_jit_compile.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "284991208664132423429566079959482933300",
                "59663981944089027375129892030352113302",
                "215502009414250523089328794008073975091",
                "66628541543409450441890529484581639807"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-1586-ec8883ab",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/pcre2project/pcre2/commit/3103b8f20a3b9944b177e812fde29fbfb8b90558",
        "target":  {
            "file":  "src/pcre2test.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T12:59:11Z"