UBUNTU-CVE-2026-2903

Source
https://ubuntu.com/security/CVE-2026-2903
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-2903.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-2903
Upstream
Published
2026-02-22T01:16:00Z
Modified
2026-02-28T06:13:33.902741Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function checkandmergespecialrules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack can only be executed locally. The exploit has been published and may be used. Patch name: febeb977936f9519a25d9fbd10ff8256358cdb97. It is suggested to install a patch to address this issue.

References

Affected packages

Ubuntu:22.04:LTS / re2c

Package

Name
re2c
Purl
pkg:deb/ubuntu/re2c@3.0-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.3-1build1
2.2-1
3.*
3.0-1

Ecosystem specific

{
    "priority_reason": "This is only a crash is a command-line tool",
    "binaries": [
        {
            "binary_version": "3.0-1",
            "binary_name": "re2c"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-2903.json"

Ubuntu:24.04:LTS / re2c

Package

Name
re2c
Purl
pkg:deb/ubuntu/re2c@3.1-1build1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1-1
3.1-1build1

Ecosystem specific

{
    "priority_reason": "This is only a crash is a command-line tool",
    "binaries": [
        {
            "binary_version": "3.1-1build1",
            "binary_name": "re2c"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-2903.json"

Ubuntu:25.10 / re2c

Package

Name
re2c
Purl
pkg:deb/ubuntu/re2c@4.3-2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.1-1
4.3-2

Ecosystem specific

{
    "priority_reason": "This is only a crash is a command-line tool",
    "binaries": [
        {
            "binary_version": "4.3-2",
            "binary_name": "re2c"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-2903.json"