The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7244