Impact
The vulnerability involves PCRE2’s JIT‑compiled matching routine, pcre2_jit. A previously copied subject is mishandled as a matching context; an incorrect free operation can occur. This memory misuse can cause an improper free, leading to a crash of the host application. The weakness represented by CWE-1341 (Improper Memory Deallocation) compromises application stability, though it does not directly provide arbitrary code execution.
Affected Systems
The PCRE2 regular expression library supplied by the PCRE Project is affected. Any installation of PCRE2 older than version 10.48 that uses the JIT matching feature is vulnerable. This includes numerous open‑source and commercial applications that embed PCRE2 for pattern matching.
Risk and Exploitability
The issue carries a CVSS score of 7.4, and an EPSS score of < 1% indicates a very low probability of exploitation. Nevertheless, the flaw still poses a high‑risk denial of service vector if an attacker can supply malicious regex input. The vulnerability is not listed in CISA’s KEV catalog, but its impact on If JIT compilation is disabled or not used, the risk is mitigated, but the vulnerability remains in the core library for code paths that still employ JIT.
OpenCVE Enrichment