Impact
An out‑of‑bounds read in the PCRE2 library occurs when the matching routine processes an invalid UTF‑8 subject string. The flaw allows a caller to read memory beyond the supplied buffer, potentially leaking sensitive data from the process. The vulnerability is classified as CWE‑125 and does not provide code execution, privilege escalation, or denial of service. The impact is limited to confidentiality because the attacker needs to supply a crafted string to the library.
Affected Systems
The affected product is the PCRE2 regular expression engine, version 10.47 and earlier. Any application that links against this library and enables the PCRE2_MATCH_INVALID_UTF option when working with input that may contain malformed UTF sequences is at risk. The vendor has released version 10.48 as the fixed build.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity. The EPSS score is not available, and the vulnerability requires the attacker to supply a crafted UTF string to the matching function, which is not trivial, especially for non‑interactive use. The CVE is not listed in the CISA KEV catalog, suggesting no known active exploitation. The safest mitigational approach is applying the vendor patch.
OpenCVE Enrichment