CVE-2026-89158: Integer Overflow
PCRE2 before 10.48, on 32-bit platforms, has a pcre2compile32 integer overflow and resultant out-of-bounds write.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.48-1
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects PCRE2 versions before 10.48 when running on 32-bit platforms. The provided information does not indicate that 64-bit platforms are affected.
What does an attacker need to exploit this?
The vector is network-based and requires no privileges or user interaction, but exploitation has high attack complexity. The flaw occurs during PCRE2's 32-bit compilation path and can result in an out-of-bounds write.
What is the remediation?
Upgrade PCRE2 to version 10.48 or later. The provided data does not specify a workaround for systems that cannot be upgraded immediately.