Gentoo resolved CVE-2019-20838 and CVE-2020-14155 in dev-libs/libpcre by stabilizing PCRE version 8.44 across supported architectures and removing vulnerable 8.42 and 8.43 ebuilds. The Gentoo advisory was closed as RESOLVED FIXED after repository cleanup was completed.
The corrected PCRE releases address a JIT subject-buffer overread triggered by particular patterns when UTF support is disabled, an integer-overflow condition while parsing a number after (?C, and a NULL-pointer dereference in pcretest. Organizations using Gentoo systems should ensure installed libpcre packages are upgraded to 8.44 or a later supported version.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Thomas Deutschmann recorded that the repository was clean and remediation for Bug 717920 was complete; the bug was marked RESOLVED FIXED.
Gentoo commit 577e461933395f3e973e0c153e3a1080cdf0a284 performed security cleanup for Bug 717920 by removing the libpcre-8.42.ebuild and libpcre-8.43.ebuild files.
Gentoo stabilized libpcre 8.44 for arm, x86, amd64, ppc, ppc64, sparc, hppa, and s390 during August and September 2020.
Sam James reported Gentoo Bug 717920 to track vulnerabilities in dev-libs/libpcre, including CVE-2019-20838 and CVE-2020-14155. Gentoo identified libpcre 8.44 as the resolution target.
PCRE 8.44 added validation for the numeric value following (?C to prevent an integer overflow and corrected a NULL dereference in pcretest.
PCRE 8.43 fixed a JIT-processing subject-buffer overread affecting UTF-disabled patterns that use \X or \R with a fixed quantifier greater than one. Yunho Kim identified the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.