CVE-2026-2903
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-404
Apagado o liberación incorrecto de recursos
Fecha de publicación:
22/02/2026
Última modificación:
22/02/2026
Descripción
*** Pendiente de traducción *** A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack can only be executed locally. The exploit has been published and may be used. Patch name: febeb977936f9519a25d9fbd10ff8256358cdb97. It is suggested to install a patch to address this issue.
Impacto
Puntuación base 4.0
4.80
Gravedad 4.0
MEDIA
Puntuación base 3.x
3.30
Gravedad 3.x
BAJA
Puntuación base 2.0
1.70
Gravedad 2.0
BAJA
Referencias a soluciones, herramientas e información
- https://github.com/oneafter/0202/blob/main/re/repro
- https://github.com/skvadrik/re2c/
- https://github.com/skvadrik/re2c/commit/febeb977936f9519a25d9fbd10ff8256358cdb97
- https://github.com/skvadrik/re2c/issues/571
- https://github.com/skvadrik/re2c/issues/571#issuecomment-3837675101
- https://vuldb.com/?ctiid_347210=
- https://vuldb.com/?id_347210=
- https://vuldb.com/?submit_755030=



