Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86145

Опубликовано: 05 сент. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

A flaw was found in PCRE2. An out-of-bounds write vulnerability exists in the pcre2_dfa_match function due to improper size checking when reusing cached workspace blocks. A remote attacker could exploit this by providing a specially crafted regular expression or a recursive pattern in conjunction with a small heap limit. This could lead to data corruption or potentially arbitrary code execution, compromising the integrity and availability of the system.

Отчет

Important: An out-of-bounds write vulnerability in the PCRE2 library, specifically within the pcre2_dfa_match function, could allow arbitrary code execution. This flaw is exploitable in Red Hat products when processing attacker-controlled regular expressions or when a recursive pattern is used in conjunction with a small, API-set heap limit, making it dependent on specific application usage patterns.

Меры по смягчению последствий

To mitigate this Improper Protection of Alternate Path vulnerability, ensure that secondary execution branches—such as the reuse of cached memory workspaces—enforce the exact same size and boundary checks as the primary memory allocation paths. Limit exposure by preventing untrusted user input from directly controlling PCRE2 regular expressions, and strictly avoid utilizing recursive matching patterns when operating under a low heap limit. Apply a defense-in-depth strategy by validating all inputs comprehensively.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bootcNot affected
Red Hat Enterprise Linux 10mariadb10.11Affected
Red Hat Enterprise Linux 10mariadb11.8Affected
Red Hat Enterprise Linux 10mingw-pcre2Affected
Red Hat Enterprise Linux 10pcre2Affected
Red Hat Enterprise Linux 7pcre2Not affected
Red Hat Enterprise Linux 8mariadb:10.11/mariadbAffected
Red Hat Enterprise Linux 8pcre2Affected
Red Hat Enterprise Linux 9bootcNot affected
Red Hat Enterprise Linux 9mariadb:10.11/mariadbAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2528993pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions

EPSS

Процентиль: 31%
0.00373
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
9 дней назад

(PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...)

CVSS3: 8.2
nvd
11 дней назад

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

msrc
10 дней назад

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

CVSS3: 8.2
debian
11 дней назад

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...

CVSS3: 8.2
github
11 дней назад

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

EPSS

Процентиль: 31%
0.00373
Низкий

8.2 High

CVSS3