ALAS2023-2023-286


Amazon Linux 2023 Security Advisory: ALAS-2023-286
Advisory Release Date: 2023-08-03 20:26 Pacific
Advisory Updated Date: 2023-08-09 23:15 Pacific
Severity: Low

Issue Overview:

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input. (CVE-2022-41409)


Affected Packages:

pcre2


Issue Correction:
Run dnf update pcre2 --releasever 2023.1.20230809 to update your system.

New Packages:
aarch64:
    pcre2-debugsource-10.40-1.amzn2023.0.3.aarch64
    pcre2-debuginfo-10.40-1.amzn2023.0.3.aarch64
    pcre2-utf16-10.40-1.amzn2023.0.3.aarch64
    pcre2-10.40-1.amzn2023.0.3.aarch64
    pcre2-tools-10.40-1.amzn2023.0.3.aarch64
    pcre2-utf32-10.40-1.amzn2023.0.3.aarch64
    pcre2-tools-debuginfo-10.40-1.amzn2023.0.3.aarch64
    pcre2-utf16-debuginfo-10.40-1.amzn2023.0.3.aarch64
    pcre2-static-10.40-1.amzn2023.0.3.aarch64
    pcre2-utf32-debuginfo-10.40-1.amzn2023.0.3.aarch64
    pcre2-devel-10.40-1.amzn2023.0.3.aarch64

noarch:
    pcre2-syntax-10.40-1.amzn2023.0.3.noarch

src:
    pcre2-10.40-1.amzn2023.0.3.src

x86_64:
    pcre2-utf32-debuginfo-10.40-1.amzn2023.0.3.x86_64
    pcre2-static-10.40-1.amzn2023.0.3.x86_64
    pcre2-10.40-1.amzn2023.0.3.x86_64
    pcre2-debuginfo-10.40-1.amzn2023.0.3.x86_64
    pcre2-utf16-debuginfo-10.40-1.amzn2023.0.3.x86_64
    pcre2-tools-debuginfo-10.40-1.amzn2023.0.3.x86_64
    pcre2-debugsource-10.40-1.amzn2023.0.3.x86_64
    pcre2-utf16-10.40-1.amzn2023.0.3.x86_64
    pcre2-tools-10.40-1.amzn2023.0.3.x86_64
    pcre2-utf32-10.40-1.amzn2023.0.3.x86_64
    pcre2-devel-10.40-1.amzn2023.0.3.x86_64