Описание
Security update for pcre2
This update for pcre2 fixes the following issues:
- CVE-2026-86145: missing size checks in
pcre2_dfa_matchcode can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054).
- CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053).
- CVE-2026-89158: out-of-bounds write due to integer overflow in
pcre2_compile_32for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the
PCRE2_MATCH_INVALID_UTFmatching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in
pcre2_jit_match(bsc#1280050). - CVE-2026-89162: information disclosure via
pcre2_serialize_encode(bsc#1280049).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1277707
- SUSE Bug 1277708
- SUSE Bug 1277709
- SUSE Bug 1277710
- SUSE Bug 1277711
- SUSE Bug 1277712
- SUSE Bug 1277713
- SUSE Bug 1279893
- SUSE Bug 1280049
- SUSE Bug 1280050
- SUSE Bug 1280051
- SUSE Bug 1280052
- SUSE Bug 1280053
- SUSE Bug 1280054
- SUSE CVE CVE-2026-86145 page
- SUSE CVE CVE-2026-89156 page
- SUSE CVE CVE-2026-89157 page
- SUSE CVE CVE-2026-89158 page
- SUSE CVE CVE-2026-89160 page
Описание
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
Затронутые продукты
Ссылки
- CVE-2026-86145
- SUSE Bug 1279893
Описание
PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
Затронутые продукты
Ссылки
- CVE-2026-89156
- SUSE Bug 1280054
Описание
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
Затронутые продукты
Ссылки
- CVE-2026-89157
- SUSE Bug 1280053
Описание
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
Затронутые продукты
Ссылки
- CVE-2026-89158
- SUSE Bug 1280052
Описание
PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.
Затронутые продукты
Ссылки
- CVE-2026-89160
- SUSE Bug 1280051
Описание
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
Затронутые продукты
Ссылки
- CVE-2026-89161
- SUSE Bug 1280050
Описание
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
Затронутые продукты
Ссылки
- CVE-2026-89162
- SUSE Bug 1280049