Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: re2c

Found 1 matching suggestions

View:
Compact
Detailed
Published
Permalink CVE-2026-2903
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 6 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package vimPlugins.nvim-treesitter-parsers.re2c
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
skvadrik re2c ast.cc check_and_merge_special_rules null pointer dereference

A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack can only be executed locally. The exploit has been published and may be used. Patch name: febeb977936f9519a25d9fbd10ff8256358cdb97. It is suggested to install a patch to address this issue.

Affected products

re2c
  • ==4.2
  • ==4.0
  • ==4.1
  • ==4.4
  • ==4.3

Matching in nixpkgs

pkgs.re2c

Tool for writing very fast and very flexible scanners

  • nixos-unstable 4.4
    • nixpkgs-unstable 4.4
    • nixos-unstable-small 4.4
Ignored packages (1)

Package maintainers

Upstream issue: https://github.com/skvadrik/re2c/issues/571
Upstream patch: https://github.com/skvadrik/re2c/commit/febeb977936f9519a25d9fbd10ff8256358cdb97