ECHO-3a0b-e277-32da

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-3a0b-e277-32da.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-3a0b-e277-32da
Upstream
Withdrawn
2026-01-06T11:30:04Z
Published
2026-01-01T10:35:25Z
Modified
2026-09-15T03:33:36Z
Summary
This vulnerability is disputed by upstream maintainers with negligible security impact. The stack consumption problem is caused by the mark_beginning_as_normal function making recursive calls to itself. The crash occurs in flex itself, not in the scanner produced by flex. The protection against exploit is to not run flex setuid, which is already the default behavior. Stack exhaustion from exceptionally long garbage input to flex is not considered a security concern. https://security-tracker.debian.org/tracker/CVE-2019-6293 https://github.com/westes/flex/issues/414
Details
References

Affected packages

Echo / flex

Package

Name
flex
Purl
pkg:deb/echo/flex

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.4-8.2+b4

Database specific

source
"https://advisory.echohq.com/osv/ECHO-3a0b-e277-32da.json"