CVE-2026-89157: Integer Overflow
PCRE2 before 10.48, on 32-bit platforms, has a pcre2patternconvert out-of-bounds write when an attacker can provide a large pattern.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.48-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.95-6
Event History
Frequently Asked Questions
Which systems are affected?
The issue affects PCRE2 versions before 10.48 running on 32-bit platforms. The described vulnerable code path is pcre2_pattern_convert.
What must an attacker provide to trigger the issue?
An attacker must be able to supply a large pattern to pcre2_pattern_convert. The vulnerability is an out-of-bounds write caused by an integer overflow.
Does exploitation require authentication or user interaction?
The supplied severity vector indicates no privileges are required and no user interaction is required. Exploitation is local and has high attack complexity.
What is the remediation?
Upgrade PCRE2 to version 10.48 or later. The issue is reported in versions before 10.48.