RHSA-2024:0572: Moderate: oniguruma security update
Moderate: oniguruma security update
Other sources
Oniguruma is a regular expressions library that supports a variety of character encodings. Security Fix(es): oniguruma: Use-after-free in onignewdeluxe() in regext.c (CVE-2019-13224) oniguruma: Stack exhaustion in regcomp.c because of recursion in regparse.c (CVE-2019-16163) oniguruma: integer overflow in searchinrange function in regexec.c leads to out-of-bounds read (CVE-2019-19012) oniguruma: Heap-based buffer over-read in function gb18030mbcenclen in file gb18030.c (CVE-2019-19203) oniguruma: Heap-based buffer over-read in function fetchintervalquantifier in regparse.c (CVE-2019-19204) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0572?
The severity of RHSA-2024:0572 is classified as moderate.
How do I fix RHSA-2024:0572?
To fix RHSA-2024:0572, update the oniguruma package to version 6.8.2-2.1.el8_8.
What vulnerabilities are addressed in RHSA-2024:0572?
RHSA-2024:0572 addresses a use-after-free vulnerability and stack exhaustion in the oniguruma regular expressions library.
Which products are affected by RHSA-2024:0572?
Affected products include Red Hat Enterprise Linux and Red Hat CodeReady Linux Builder for various architectures like x86_64, ARM 64, and Power.
Is there a specific version of oniguruma required for the fix in RHSA-2024:0572?
Yes, the specific version required for the fix in RHSA-2024:0572 is 6.8.2-2.1.el8_8.