From https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.49 """ This is a security-only release, to address GHSA-r9hj-j2rw-4q3m.
Compared to 10.48, this release has only a minimal code change to prevent an out-of-bounds write with arbitrary data. An attacker-controlled regular expression is required. Applications are affected only when they use pcre2_jit_stack_create() and pcre2_jit_stack_assign() to provide a growable JIT stack, then match a pattern with unusually high JIT stack usage, such as one containing a large number of capturing groups. The implications of an out-of-bounds write could include arbitrary code execution. The issue is not a regression and affects releases 10.48 and earlier. Users should upgrade to 10.49. Backport patches for supported earlier releases are listed in SUPPORT-LIFECYCLE.md. This release is available as a signed Git tag, or alternatively as a signed tarball of the Git tag (attestation). """ My default response to these is always "OK, how realistic is attacker-controlled $X?", but libpcre2's maintainers are quite sensible, and indeed, reading the advisory [0], it had some interesting detail. Quoting just a bit of that: """ Summary Maintainer note: This vulnerability is not specific to phpMyAdmin, and may affect other PHP software, and other software using PCRE2. While testing phpMyAdmin 5.2.3, I developed a lab proof of concept that achieved command execution through phpMyAdmin's use of an attacker-controlled regular expression. Root-cause analysis of the memory corruption led to an independent vulnerability in the PCRE2 8-bit JIT. An attacker-controlled pattern can make the JIT write below its stack mapping. The escaped writes can corrupt a separate allocation and include pointers into the attacker-controlled subject buffer. I reproduced the issue with clean official PCRE2 10.48 builds on Linux/AArch64, macOS/ARM64, and macOS/x86_64 under Rosetta. The same stack boundary failure is also present in PCRE2 10.42 with an earlier trigger. I have not identified the first affected release or tested other JIT backends. """ [I'm reluctant to just paste the whole advisory text from my browser but haven't looked to see if there's a convenient way to get a plaintext advisory from GHSAs, like GitHub supports for PRs & commits (.patch + .diff). If someone is aware of such a way, let me know please!] [0] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m sam
signature.asc
Description: PGP signature
