CVE-2015-1345: GNU Grep

Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.

Affected products

  • GNU Grep: version 2.19 only; version 2.20 only; version 2.21 only
  • Opensuse Opensuse: version 13.2 only

Published 2015-02-12. Last modified 2026-06-17.