CVE-2020-11958: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 1.7% chance of exploitation in the next 30 days.

re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.

Affected products

  • Canonical Ubuntu Linux: version 19.10 only; version 20.04 only
  • RE2C RE2C: version 1.3 only

Published 2020-04-21. Last modified 2026-06-17.