CVE-2026-89156

Published: September 13, 2026Last modified: October 1, 2026

Description

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

Severity score breakdown

ParameterValue
Base score5.9
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux25 LTSpcre2Fixed (10.48-r0)
Streampcre2Fixed (10.48-r0)
Hardened Containers25 LTSpcre2Fixed (10.48-r0)
Streampcre2Fixed (10.48-r0)

References

ON THIS PAGE