SUSE-SU-2026:4201-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4201-1
SUSE-SU-2026:4201-1
Summary: Security update for pcre2
Details: This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050).
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264201-1/, https://bugzilla.suse.com/1277707, https://bugzilla.suse.com/1277708, https://bugzilla.suse.com/1277709, https://bugzilla.suse.com/1277710, https://bugzilla.suse.com/1277711, https://bugzilla.suse.com/1277713, https://bugzilla.suse.com/1279893, https://bugzilla.suse.com/1280050, https://bugzilla.suse.com/1280051, https://bugzilla.suse.com/1280052, https://bugzilla.suse.com/1280053, https://bugzilla.suse.com/1280054, https://www.suse.com/security/cve/CVE-2026-86145, https://www.suse.com/security/cve/CVE-2026-89156, https://www.suse.com/security/cve/CVE-2026-89157, https://www.suse.com/security/cve/CVE-2026-89158, https://www.suse.com/security/cve/CVE-2026-89160, https://www.suse.com/security/cve/CVE-2026-89161
Affected packages
Package
Name: pcre2
Purl: pkg:rpm/suse/pcre2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS
Affected ranges
Type: ECOSYSTEM
Events:
