https://seclists.org/oss-sec/2026/q3/723: pc2 version 10.48 leased with security fixes
Affected Software
Frequently Asked Questions
What application behavior is required for the JIT-related out-of-bounds read to occur?
The application must call pcre2_jit_compile() with options for certain match modes, then call pcre2_match() using a different match mode. The attempted match must also be against invalid UTF input.
Which issues are specifically relevant to 32-bit platforms?
The pcre2_convert() issue applies on platforms with a 32-bit size_t when conversion is performed on untrusted input. Separate integer-overflow checks were added for pattern compilation on 32-bit CPUs, where under-allocation could otherwise lead to out-of-bounds writes.
When is the DFA matching flaw relevant?
It is relevant when DFA matching is used with a heap limit. The fixes address an out-of-bounds write and possible integer overflows that could under-allocate the workspace.
Does processing untrusted data matter for any of these issues?
Yes. CVE-2026-89157 is triggered by calling pcre2_convert() on untrusted input on a platform with 32-bit size_t. The JIT-related issue also requires invalid UTF input to be matched.