https://seclists.org/oss-sec/2026/q3/723: pc2 version 10.48 leased with security fixes

Published Sep 11, 2026
·
Updated

Affected Software

1 affected component
pcre2=10.48

Frequently Asked Questions

1

What application behavior is required for the JIT-related out-of-bounds read to occur?

The application must call pcre2_jit_compile() with options for certain match modes, then call pcre2_match() using a different match mode. The attempted match must also be against invalid UTF input.

2

Which issues are specifically relevant to 32-bit platforms?

The pcre2_convert() issue applies on platforms with a 32-bit size_t when conversion is performed on untrusted input. Separate integer-overflow checks were added for pattern compilation on 32-bit CPUs, where under-allocation could otherwise lead to out-of-bounds writes.

3

When is the DFA matching flaw relevant?

It is relevant when DFA matching is used with a heap limit. The fixes address an out-of-bounds write and possible integer overflows that could under-allocate the workspace.

4

Does processing untrusted data matter for any of these issues?

Yes. CVE-2026-89157 is triggered by calling pcre2_convert() on untrusted input on a platform with 32-bit size_t. The JIT-related issue also requires invalid UTF input to be matched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203