CVE-2022-24713 is a Denial of Service vulnerability affecting the Rust regex crate versions 1.5.4 and earlier, impacting products like Debian and Fedora that utilize it. The vulnerability stems from a flaw in the regex crate's built-in mitigations, allowing specially crafted untrusted regular expressions to bypass these safeguards and consume excessive resources. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and can lead to a complete denial of service for affected systems. While there is no evidence of active exploitation, no public exploit code, and it is not on the CISA KEV catalog, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.5CPE matchmatch criteria | cpe:2.3:a:rust-lang:regex:*:*:*:*:*:rust:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-24713
Sep 10, 2024Mozilla: Denial of Service via complex regular expressions
Apr 5, 2022Rust's regex crate vulnerable to regular expression denial of service
Mar 8, 2022Regular expression denial of service in Rust's regex crate
Mar 8, 2022