CVE-2026-89161

Published: September 13, 2026Last modified: October 1, 2026

Description

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux25 LTSpcre2Fixed (10.48-r0)
Streampcre2Fixed (10.48-r0)
Hardened Containers25 LTSpcre2Fixed (10.48-r0)
Streampcre2Fixed (10.48-r0)

References

ON THIS PAGE