Impact
PCRE2 integer overflow in the pcre2_compile_32 function on 32‑bit platforms can cause an out‑of‑bounds write that corrupts memory, potentially allowing a malicious actor to influence program control flow or crash the system.
Affected Systems
The affected product is the PCRE library (PCRE:PCRE2) on 32‑bit operating systems. Every release prior to 10.48 is vulnerable; version 10.48 and later contain the fix.
Risk and Exploitability
The CVSS score severity vulnerability. The EPSS score of <1% indicates an extremely low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A malicious regular expression that triggers the integer overflow during compilation would need to be processed by a vulnerable PCRE2 instance on a 32‑bit platform, limiting the attack surface to contexts where untrusted input is compiled by PCRE2.
OpenCVE Enrichment