CVE-2022-41409Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.
CWE-190 · Integer overflow
Proof of concept only
A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.
CVSS E:P
Not a Java vulnerability. Outside ARMR's domain entirely.
| Decided by | non-java-upstream : A root cause in non-Java code: an OS kernel, a C library, or a bundled runtime |
|---|---|
| Finding | The issuing CNA declared no affected product. The CVE's CPE data names pcre/pcre2, whose code is not Java, so that is what the CVE is about — every other product on the record bundles it. |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 metric
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
NVD | Primary | published |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update October 2023 ↗ | CPU | 2023-Q4 | Oracle Analytics / Analytics Server (PCRE2) (6.4.0.0.0, 7.0.0.0.0) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Analytics | Analytics Server (PCRE2) | 6.4.0.0.0, 7.0.0.0.0 | 6.4.0.0.0 · 7.0.0.0.0 |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | pcre | pcre2 | generic | < 10.41 |
| URL | Tags |
|---|---|
| https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35 | Patch |
| https://github.com/PCRE2Project/pcre2/issues/141 | Exploit, Third Party Advisory |
| Published | 2023-07-18 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |