Impact
This vulnerability is an out‑of‑bounds write in PCRE2 enabled by the JIT compilation API when an attacker supplies a crafted regular expression. The flaw allows arbitrary data to be written outside the intended buffer, resulting in memory corruption.
Affected Systems
Any system that links with PCRE2 versions earlier than 10.49 and uses the JIT compiler to evaluate externally supplied regular expressions is impacted. The affected library is PCRE2, identified by the CNA vendor/product name PCRE:PCRE2.
Risk and Exploitability
The CVSS score of 7.6 denotes high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw by presenting a malicious regular expression to an application that invokes the JIT API, giving them a method to corrupt memory. The risk remains elevated when untrusted input is processed without mitigating controls such as disabling JIT or avoiding JIT on user‑supplied expressions.
OpenCVE Enrichment