CVE-2026-86145

Published: September 8, 2026Last modified: September 17, 2026

Description

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

Severity score breakdown

ParameterValue
Base score8.2
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpcre2Unknown (10.40-r1)
25 LTSpcre2Unknown (10.43-r1)
Streampcre2Fixed (10.48-r0)
Hardened Containers23 LTSpcre2Unknown (10.40-r1)
25 LTSpcre2Unknown (10.43-r1)
Streampcre2Unknown (10.40-r1)

References

ON THIS PAGE