CVE & CISA-KEV Catalog

CVE-2022-24713

HIGHEPSS 96th pctl
7.5
CVSS v3
NVD

Description

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex crate. Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, it us not recommend to deny known problematic regexes.

How to fix

Remediation Available
firefoxDebian
Fixed in:99.0-1CVE-2022-24713
firefoxUbuntu
Fixed in:99.0+build2-0ubuntu0.18.04.2USN-5370-1
Fixed in:99.0+build2-0ubuntu0.20.04.2USN-5370-1
librust-regex-devUbuntu
Fixed in:1.2.1-3ubuntu0.1USN-5610-1
Fixed in:1.5.4-1ubuntu0.1USN-5610-1
rust-regexUbuntu
Fixed in:1.2.1-3ubuntu0.1USN-5610-1
Fixed in:1.5.4-1ubuntu0.1USN-5610-1

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityNone
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploit Intelligence

14.46%probability of exploitation in 30 days
96thpercentile

Very high risk: more likely to be exploited than 96% of all known CVEs.

References

Related Vulnerabilities

Other CWE-400 (Resource Exhaustion) vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2023-44487High7.5100%KEVFix
CVE-2021-44228Critical10.0100%KEV + RansomFix
CVE-2011-3192High7.899%-Fix
CVE-2019-11478Medium5.395%-Fix
CVE-2024-25617Medium5.389%-Fix
CVE-2018-1000115High7.588%-Fix
Embed a live status badge for CVE-2022-24713
CVE-2022-24713 severity badge

Markdown

[![CVE-2022-24713](https://tridentstack.com/cve/badge/CVE-2022-24713.svg)](https://tridentstack.com/cve/CVE-2022-24713)

HTML

<a href="https://tridentstack.com/cve/CVE-2022-24713"><img src="https://tridentstack.com/cve/badge/CVE-2022-24713.svg" alt="CVE-2022-24713"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.