Impact
The vulnerability resides in the pcre2_pattern_convert function of PCRE2 before version 10.48 on 32-bit platforms. When an attacker supplies a very large regular expression, the function writes beyond the bounds of the internal buffer. This out-of-bounds write corrupts adjacent memory, which can crash the process or corrupt data. The flaw is (CWE-190) and an out-of-bounds write (CWE-787) and can be triggered by untrusted input.
Affected Systems
The affected library is PCRE:PCRE2, any installation of 10.48 or earlier on 32-bit platforms, and it affects all binaries that link against the vulnerable library.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity; the EPSS score is < 1%, showing a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a crafted regex pattern to an application that uses PCRE2, which is often a local or remote service that compiles user-supplied patterns. The overflow can lead to a crash; if an attacker can control the overwritten data, there is a potential for local code execution inferred from the nature of the buffer corruption. In practice, the risk is limited to applications that expose raw regex compilation to untrusted users, and the likelihood of widespread exploitation remains low without a publicly available exploit.
OpenCVE Enrichment