PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Write in PCRE2 DFA Matching Due to Cached Workspace Size Check Missing |
Sat, 05 Sep 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API). | |
| First Time appeared |
Pcre
Pcre pcre2 |
|
| Weaknesses | CWE-424 | |
| CPEs | cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pcre
Pcre pcre2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T05:09:25.571Z
Reserved: 2026-09-05T05:09:25.213Z
Link: CVE-2026-86145
No data.
Status : Received
Published: 2026-09-05T06:17:10.370
Modified: 2026-09-05T06:17:10.370
Link: CVE-2026-86145
No data.
OpenCVE Enrichment
Updated: 2026-09-05T06:30:04Z
Weaknesses