LiveActive security incident?Get immediate response
CVE Record

CVE-2022-41409: Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or o...

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2022-41409 is an integer overflow in PCRE2's pcre2test utility before version 10.41. A specially formed negative input can crash or disrupt the utility, with other impacts not clearly described in the sources. Business risk is mainly where pcre2test processes untrusted input in automation or exposed tooling.

Executive priority

Treat this as a targeted hygiene item rather than an emergency unless pcre2test is reachable by users or automation handling untrusted data. Prioritize developer, CI, and production images that include PCRE2 utilities and update them through normal patch channels.

Technical view

The issue affects pcre2test before 10.41 and is described as an integer overflow reachable through negative input. Public sources identify denial of service and unspecified possible impacts, but do not provide CVSS, CWE mapping, or broad product exposure details. The cited upstream commit appears to be the corrective change.

Likely exposure

Exposure is likely limited to environments that install or run pcre2test and allow untrusted regex test data or negative input values. The sources do not show that normal PCRE2 library consumers are affected unless they invoke the utility.

Exploitation context

The source bundle does not cite active exploitation, and the CVE is not marked in KEV. Public evidence supports potential denial of service against pcre2test, but not weaponized exploitation, internet-scale exploitation, or confirmed impact beyond the utility.

Researcher notes

The public record is sparse: no CVSS, CWE, affected CPEs, or detailed impact analysis are provided in the bundle. Analysis should stay scoped to pcre2test before 10.41, negative input handling, and denial-of-service risk unless additional vendor evidence expands scope.

Mitigation direction

  • Upgrade PCRE2/pcre2test to version 10.41 or later where available.
  • Apply vendor package updates for systems shipping PCRE2 utilities.
  • Restrict pcre2test from processing untrusted input in automated workflows.
  • Remove pcre2test from production images if not operationally required.
  • Monitor upstream PCRE2 and distribution advisories for additional guidance.

Validation and detection

  • Inventory hosts and containers for installed pcre2test versions below 10.41.
  • Check build, CI, and support tooling for pcre2test usage with external input.
  • Confirm package manager or source builds include the upstream fix commit.
  • Review logs for unexpected pcre2test crashes in exposed automation paths.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-41409 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.