CVE-2014-7926: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 14.10 only
  • Google Chrome: up to and including 40.0.2214.85
  • Icu-Project International Components For Unicode: before 55.1 (fixed in 55.1)
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Oracle Communications Messaging Server: version 7.0.5 only; version 8.0 only
  • Red Hat Enterprise Linux Desktop Supplementary: version 6.0 only
  • Red Hat Enterprise Linux Server Supplementary: version 6.0 only
  • Red Hat Enterprise Linux Server Supplementary Eus: version 6.6.z only
  • Red Hat Enterprise Linux Workstation Supplementary: version 6.0 only

Published 2015-01-22. Last modified 2026-06-17.