CVE-2026-89158: Integer Overflow
Published Sep 11, 2026
·Updated
PCRE2 before 10.48, on 32-bit platforms, has a pcre2compile32 integer overflow and resultant out-of-bounds write.
Affected Software
1 affected component
PCRE2 PCRE2<10.48
Event History
Sep 11, 2026
CVE Published
via MITRE·04:07 AM
Data Sourced
via MITRE·04:07 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects PCRE2 versions before 10.48 when running on 32-bit platforms. The provided information does not indicate that 64-bit platforms are affected.
2
What does an attacker need to exploit this?
The vector is network-based and requires no privileges or user interaction, but exploitation has high attack complexity. The flaw occurs during PCRE2's 32-bit compilation path and can result in an out-of-bounds write.
3
What is the remediation?
Upgrade PCRE2 to version 10.48 or later. The provided data does not specify a workaround for systems that cannot be upgraded immediately.