Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-89162

Опубликовано: 11 сент. 2026
Источник: redhat
CVSS3: 2.9
EPSS Низкий

Описание

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

A flaw was found in PCRE2. The pcre2_serialize_encode function might disclose two bytes of information to an attacker. This vulnerability typically occurs in scenarios where the attacker already has unsafe access to the system, making exploitation difficult. The primary impact is a limited information disclosure.

Отчет

This is a information disclosure flaw in PCRE2. The vulnerability, which could expose two bytes of data, requires an adversary to have already gained unsafe access to the system, significantly limiting its exploitability in typical Red Hat deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bootcNot affected
Red Hat Enterprise Linux 10mariadb10.11Fix deferred
Red Hat Enterprise Linux 10mariadb11.8Fix deferred
Red Hat Enterprise Linux 10mingw-pcre2Not affected
Red Hat Enterprise Linux 10pcre2Not affected
Red Hat Enterprise Linux 7pcre2Not affected
Red Hat Enterprise Linux 8mariadbFix deferred
Red Hat Enterprise Linux 8pcre2Not affected
Red Hat Enterprise Linux 9bootcNot affected
Red Hat Enterprise Linux 9mariadbFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2531748pcre2: PCRE2: Information disclosure via pcre2_serialize_encode

EPSS

Процентиль: 1%
0.00105
Низкий

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
2 дня назад

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

CVSS3: 2.9
nvd
5 дней назад

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

CVSS3: 2.9
debian
5 дней назад

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes ...

CVSS3: 2.9
github
5 дней назад

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

EPSS

Процентиль: 1%
0.00105
Низкий

2.9 Low

CVSS3