The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade grep. | Aug 30, 2017 | Feb 12, 2015 |
| Debian | — | Upgrade grep | Jul 30, 2024 | Feb 12, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jun 29, 2017 |
| Gentoo Linux | — | Upgrade sys-apps/grep. | Oct 30, 2017 | Feb 12, 2015 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Feb 12, 2015 |
| Oracle_linux | — | Upgrade grep | Oct 16, 2024 | Feb 12, 2015 |
| Suse | — | Upgrade grepUpgrade grep-lang | Dec 18, 2015 | Feb 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub