CVE-2026-86145

Public on 2026-09-05
Modified on 2026-09-08
Description
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core pcre Not Affected
Amazon Linux 2023 pcre Not Affected
Amazon Linux 2 - Core pcre2 Not Affected
Amazon Linux 2023 pcre2 Pending Fix
Amazon Linux 2027 Preview pcre2 Pending Fix
Amazon Linux 2 - Php8.2 Extra php Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H