CVE-2014-9769: Pcre
High severity, CVSS 7.3. EPSS: 2.4% chance of exploitation in the next 30 days.
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset.
Affected products
- Pcre Pcre: version 8.35 only
Published 2016-03-28. Last modified 2026-06-17.