Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-89158

Опубликовано: 11 сент. 2026
Источник: redhat
CVSS3: 6.5

Описание

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

A flaw was found in PCRE2. On 32-bit platforms, an integer overflow in the pcre2_compile_32 function can lead to an out-of-bounds write. This vulnerability could allow a remote attacker to achieve a high integrity impact and a low availability impact, potentially leading to data corruption or denial of service.

Отчет

A Moderate impact flaw was found in PCRE2 affecting 32-bit platforms, where an integer overflow in the pcre2_compile_32 function can lead to an out-of-bounds write. While exploitable over the network without requiring user interaction or privileges, the high attack complexity reduces its overall severity. Successful exploitation could result in high integrity impact, such as data corruption, or a low availability impact, leading to a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bootcFix deferred
Red Hat Enterprise Linux 10mariadb10.11Fix deferred
Red Hat Enterprise Linux 10mariadb11.8Fix deferred
Red Hat Enterprise Linux 10mingw-pcre2Fix deferred
Red Hat Enterprise Linux 10pcre2Affected
Red Hat Enterprise Linux 7pcre2Fix deferred
Red Hat Enterprise Linux 8mariadb:10.11/mariadbFix deferred
Red Hat Enterprise Linux 8pcre2Affected
Red Hat Enterprise Linux 9bootcFix deferred
Red Hat Enterprise Linux 9mariadb:10.11/mariadbFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2531746PCRE2: PCRE2: Out-of-bounds write via integer overflow on 32-bit platforms

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 дня назад

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

CVSS3: 6.5
nvd
5 дней назад

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

msrc
4 дня назад

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

CVSS3: 6.5
debian
5 дней назад

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 intege ...

CVSS3: 6.5
github
5 дней назад

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

6.5 Medium

CVSS3