UBUNTU-CVE-2017-8399

Source
https://ubuntu.com/security/CVE-2017-8399
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-8399.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-8399
Upstream
Withdrawn
2025-07-18T16:43:58Z
Published
2017-05-01T18:59:00Z
Modified
2025-07-16T07:18:31.637471Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."

References

Affected packages

Ubuntu:16.04:LTS / pcre2

Package

Name
pcre2
Purl
pkg:deb/ubuntu/pcre2@10.21-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.21-1

Affected versions

10.*
10.20-1
10.20-2
10.20-3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libpcre2-16-0",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-16-0-dbgsym",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-32-0",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-32-0-dbgsym",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-8-0",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-8-0-dbgsym",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-dbg",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-dev",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-dev-dbgsym",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-posix0",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "libpcre2-posix0-dbgsym",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "pcre2-utils",
            "binary_version": "10.21-1"
        },
        {
            "binary_name": "pcre2-utils-dbgsym",
            "binary_version": "10.21-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-8399.json"

Ubuntu:18.04:LTS / pcre2

Package

Name
pcre2
Purl
pkg:deb/ubuntu/pcre2@10.31-2?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.31-2

Affected versions

10.*
10.22-3
10.22-4
10.22-5
10.22-6

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libpcre2-16-0",
            "binary_version": "10.31-2"
        },
        {
            "binary_name": "libpcre2-32-0",
            "binary_version": "10.31-2"
        },
        {
            "binary_name": "libpcre2-8-0",
            "binary_version": "10.31-2"
        },
        {
            "binary_name": "libpcre2-8-0-udeb",
            "binary_version": "10.31-2"
        },
        {
            "binary_name": "libpcre2-dbg",
            "binary_version": "10.31-2"
        },
        {
            "binary_name": "libpcre2-dev",
            "binary_version": "10.31-2"
        },
        {
            "binary_name": "libpcre2-posix0",
            "binary_version": "10.31-2"
        },
        {
            "binary_name": "pcre2-utils",
            "binary_version": "10.31-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-8399.json"