Description
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption via out‑of‑bounds write
Action: Patch immediately
AI Analysis

Impact

PCRE2 integer overflow in the pcre2_compile_32 function on 32‑bit platforms can cause an out‑of‑bounds write that corrupts memory, potentially allowing a malicious actor to influence program control flow or crash the system.

Affected Systems

The affected product is the PCRE library (PCRE:PCRE2) on 32‑bit operating systems. Every release prior to 10.48 is vulnerable; version 10.48 and later contain the fix.

Risk and Exploitability

The CVSS score severity vulnerability. The EPSS score of <1% indicates an extremely low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A malicious regular expression that triggers the integer overflow during compilation would need to be processed by a vulnerable PCRE2 instance on a 32‑bit platform, limiting the attack surface to contexts where untrusted input is compiled by PCRE2.

Generated by OpenCVE AI on September 21, 2026 at 04:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PCRE2 to version 10.48 or later as published on the PCRE project releases page, which fixes the integer overflow and out‑of‑bounds write (CWE-787).
  • If an immediate upgrade is not feasible, temporarily disable or isolate any components that compile untrusted regular expressions on 32‑bit platforms until the vulnerability is resolved, mitigating the memory corruption risk (CWE-787).
  • Continue to keep the system patched with the latest PCRE2 releases and monitor official advisories for additional patches or workarounds to mitigate the integer overflow issue.

Generated by OpenCVE AI on September 21, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pcre:pcre2:10.48:rc1:*:*:*:*:*:*

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title PCRE2 Integer Overflow in 32‑bit Compilation Function Leading to Out‑of‑Bounds Write PCRE2: PCRE2: Out-of-bounds write via integer overflow on 32-bit platforms
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title PCRE2 Integer Overflow in 32‑bit Compilation Function Leading to Out‑of‑Bounds Write

Fri, 11 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
First Time appeared Pcre
Pcre pcre2
Weaknesses CWE-190
CPEs cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*
Vendors & Products Pcre
Pcre pcre2
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T14:09:19.448Z

Reserved: 2026-09-11T04:07:21.613Z

Link: CVE-2026-89158

cve-icon Vulnrichment

Updated: 2026-09-11T14:09:14.933Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T04:18:03.970

Modified: 2026-09-16T19:23:41.450

Link: CVE-2026-89158

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T04:07:21Z

Links: CVE-2026-89158 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses