Description
A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack can only be executed locally. The exploit has been published and may be used. Patch name: febeb977936f9519a25d9fbd10ff8256358cdb97. It is suggested to install a patch to address this issue.
Problem types
Product status
4.1
4.2
4.3
4.4
Timeline
| 2026-02-20: | Advisory disclosed |
| 2026-02-20: | VulDB entry created |
| 2026-02-20: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.347210 (VDB-347210 | skvadrik re2c ast.cc check_and_merge_special_rules null pointer dereference)
vuldb.com/?ctiid.347210 (VDB-347210 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.755030 (Submit #755030 | skvadrik re2c 04f1424 NULL Pointer Dereference)
github.com/skvadrik/re2c/issues/571
github.com/skvadrik/re2c/issues/571
github.com/oneafter/0202/blob/main/re/repro
github.com/...ommit/febeb977936f9519a25d9fbd10ff8256358cdb97
github.com/skvadrik/re2c/