Description
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
Published: 2026-09-11
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption leading to potential denial of service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the pcre2_pattern_convert function of PCRE2 before version 10.48 on 32-bit platforms. When an attacker supplies a very large regular expression, the function writes beyond the bounds of the internal buffer. This out-of-bounds write corrupts adjacent memory, which can crash the process or corrupt data. The flaw is (CWE-190) and an out-of-bounds write (CWE-787) and can be triggered by untrusted input.

Affected Systems

The affected library is PCRE:PCRE2, any installation of 10.48 or earlier on 32-bit platforms, and it affects all binaries that link against the vulnerable library.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity; the EPSS score is < 1%, showing a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a crafted regex pattern to an application that uses PCRE2, which is often a local or remote service that compiles user-supplied patterns. The overflow can lead to a crash; if an attacker can control the overwritten data, there is a potential for local code execution inferred from the nature of the buffer corruption. In practice, the risk is limited to applications that expose raw regex compilation to untrusted users, and the likelihood of widespread exploitation remains low without a publicly available exploit.

Generated by OpenCVE AI on September 21, 2026 at 04:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to PCRE2 10.48 or later.
  • If an upgrade is not possible, enforce input limits on regex patterns before invoking PCRE2, rejecting patterns that exceed a safe size threshold.
  • Monitor application logs and crash reports for indications of memory corruption or segmentation faults caused by regex processing.

Generated by OpenCVE AI on September 21, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pcre:pcre2:10.48:rc1:*:*:*:*:*:*

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in pcre2_pattern_convert on 32‑bit PCRE2 pcre2: PCRE2: Out-of-bounds write via large pattern input
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in pcre2_pattern_convert on 32‑bit PCRE2

Fri, 11 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
First Time appeared Pcre
Pcre pcre2
Weaknesses CWE-190
CPEs cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*
Vendors & Products Pcre
Pcre pcre2
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T16:02:46.326Z

Reserved: 2026-09-11T04:05:26.609Z

Link: CVE-2026-89157

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T04:18:03.753

Modified: 2026-09-16T19:25:08.880

Link: CVE-2026-89157

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T04:05:27Z

Links: CVE-2026-89157 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:00:14Z

Weaknesses