Impact
The vulnerability resides in PCRE2 and triggers an out-of-bounds read during the JIT fallback path of the pcre2_match function when an attacker supplies malformed UTF data. The read can access memory locations beyond the intended bounds, which may result in exposure of arbitrary process memory contents. The weakness is identified as CWE-125.
Affected Systems
All PCRE2 builds prior to version 10.48 are affected. Any system that incorporates PCRE2 10.47 or older – including applications, libraries, or services that use PCRE2 for regular expression processing – is susceptible if they do not upgrade to 10.48 or later.
Risk and Exploitability
The CVSS score of 2.9 indicates a low severity. Since the EPSS score is not available, current exploitation activity cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog, the exploitation likelihood appears limited. The attack requires the ability to provide crafted UTF input to the PCRE2 engine; thus the vector is typically local or remote code execution contexts that involve regular expression handling.
OpenCVE Enrichment