CVE-2019-9192
CVE Details
Visit the official vulnerability details page for CVE-2019-9192 to learn more.
Initial Publication
10/25/2024
Last Update
09/02/2025
Third Party Dependency
libc6
NIST CVE Summary
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern
CVE Severity
Our Official Summary
This CVE is reported in the GNU C Library (aka glibc or libc6) through 2.29. Upstream does not consider this to be a security issue, per https://sourceware.org/glibc/wiki/Security%20Exceptions and no fix is available. This issue has been disputed and marked as not a security issue.
Status
Ongoing
Affected Products & Versions
Version | Palette Enterprise | Palette Enterprise Airgap | VerteX | VerteX Airgap |
---|---|---|---|---|
4.7.16 | ⚠️ Impacted | ✅ No Impact | ⚠️ Impacted | ⚠️ Impacted |
4.6.41 | ⚠️ Impacted | ⚠️ Impacted | ⚠️ Impacted | ⚠️ Impacted |
4.5.22 | ⚠️ Impacted | ⚠️ Impacted | ⚠️ Impacted | ⚠️ Impacted |
4.4.20 | ⚠️ Impacted | ⚠️ Impacted | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.