PT-2026-103020 · Pcre2 · Pcre2
CVE-2026-103111
·
Published
2026-09-30
·
Updated
2026-09-30
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
PCRE2 versions prior to 10.49
Description
An out-of-bounds write occurs when an attacker-controlled regular expression is used in conjunction with specific JIT API usage. This issue affects the
pcre2 jit compile() and pcre2 jit match() functions, allowing the writing of arbitrary data outside the intended memory boundaries, which may lead to system crashes or potential code execution. Non-JIT matching paths are not impacted. JIT (Just-In-Time) compilation is a method used to improve performance by compiling regular expressions into machine code at runtime.Recommendations
Upgrade to version 10.49.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pcre2