On 9/4/26 16:25, Alan Coopersmith wrote:
* (Security fix for very specific API usage, GHSA-2p8c-ff85-vh9x) If
pcre2_jit_compile() is called with options for some match modes, and then
pcre2_match() is used to perform a match for a different match mode, an
out-of-bounds read can occur if the match is attempted against invalid UTF
input.
This is now assigned CVE-2026-89156.
* (Security fix for pattern conversion, GHSA-q8g2-wprr-34m9) If pcre2_convert()
is called on untrusted input on platforms with 32-bit size_t, an out-of-bounds
heap write can occur.
This is now assigned CVE-2026-89157.
* (Security fix, GHSA-3r4p-g7gg-ppmf) Fixed an out-of-bounds write in DFA
matching when using a heap limit; also fixed possible integer overflows which
could cause under-allocation of the workspace.
As Salvatore previously noted, this one got CVE-2026-86145.
* (Security fix, GHSA-fmgr-6ggq-9859) Added bounds checks for several integer
overflows while compiling patterns on 32-bit CPUs, which could cause
under-allocation followed by out-of-bounds writes.
This is now assigned CVE-2026-89158.
* (Security fix, GHSA-9qww-pwc4-77qq) Applied lower buffer bound to prevent
two out-of-bounds reads while scanning backwards through invalid UTF data with
PCRE2_MATCH_INVALID_UTF.
This is now assigned CVE-2026-89160.
* (Security fix for very specific API usage, #937) Fixed a leak and later
invalid free when calling the fast-path pcre2_jit_match() function with a match
data object previously used with pcre2_match() and
PCRE2_COPY_MATCHED_SUBJECT.
This is now assigned CVE-2026-89161.
* (Low-severity security fix, GHSA-q7rw-r7qq-2hx6) Fixed exposure of two
uninitialised bytes from malloc() via pcre2_serialize_encode().
This is now assigned CVE-2026-89162.
--
-Alan Coopersmith- [email protected]
Oracle Solaris Engineering - https://blogs.oracle.com/solaris