{"id":"ECHO-3a0b-e277-32da","summary":"This vulnerability is disputed by upstream maintainers with negligible security impact.\nThe stack consumption problem is caused by the mark_beginning_as_normal function making\nrecursive calls to itself. The crash occurs in flex itself, not in the scanner produced\nby flex. The protection against exploit is to not run flex setuid, which is already the\ndefault behavior. Stack exhaustion from exceptionally long garbage input to flex is not\nconsidered a security concern.\nhttps://security-tracker.debian.org/tracker/CVE-2019-6293\nhttps://github.com/westes/flex/issues/414\n","modified":"2026-09-15T03:33:36.336482268Z","published":"2026-01-01T10:35:25.682770Z","withdrawn":"2026-01-06T11:30:04.356Z","upstream":["CVE-2019-6293"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2019-6293"}],"affected":[{"package":{"name":"flex","ecosystem":"Echo","purl":"pkg:deb/echo/flex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.4-8.2+b4"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-3a0b-e277-32da.json"}}],"schema_version":"1.9.0"}