CVE-2017-11164

Publication date 11 July 2017

Last updated 7 August 2026


Ubuntu priority

Negligible

Why this priority?

Cvss 3 Severity Score

7.5 · High

Score breakdown

Description

In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.

Read the notes from the security team

Status

Package Ubuntu Release Status
pcre3 26.04 LTS resolute Not in release
25.10 questing Ignored end of life, was needed
25.04 plucky Ignored end of life, was needed
24.10 oracular Ignored end of life, was needed
24.04 LTS noble Ignored see notes
23.10 mantic Ignored end of life, was needed
23.04 lunar Ignored end of life, was needed
22.10 kinetic Ignored end of life, was needed
22.04 LTS jammy Ignored see notes
21.10 impish Ignored end of life
21.04 hirsute Ignored end of life
20.10 groovy Ignored end of life
20.04 LTS focal Ignored end of standard support, was needed
19.10 eoan Ignored end of life
19.04 disco Ignored end of life
18.10 cosmic Ignored end of life
18.04 LTS bionic Ignored end of standard support, was needed
17.10 artful Ignored end of life
17.04 zesty Ignored end of life
16.10 yakkety Ignored end of life
16.04 LTS xenial Ignored end of standard support, was needed
14.04 LTS trusty Ignored end of standard support

Notes


sbeattie

reproducer in oss-security posting. to exploit this requires an application take regular expressions as untrusted input (not just the string to match against), which is generally not safe to do with pcre.


mdeslaur

as of 2026-07-21, there is not fix for this issue, it is a limitation of pcre3. Per the author: "Stack exhaustion is a FEP (frequently encountered problem) in PCRE1 (the 8.xx series). There are various limiting options that the user can apply to limit stack usage." We will not be fixing this issue in Ubuntu. Marking as ignored.

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.5 · High

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H


Access our resources on patching vulnerabilities