** DISPUTED ** In the GNU C Library (aka glibc or libc6)...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Mar 30, 2024
Description
Published by the National Vulnerability Database
Feb 26, 2019
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Mar 30, 2024
** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\1\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern.
References