| Name | CVE-2026-103111 |
| Description | GHSA-r9hj-j2rw-4q3m: PCRE2: out-of-bounds write in JIT matching with large stack allocations |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-6530-1 |
| Debian Bugs | 1149217 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| pcre2 (PTS) | bookworm | 10.42-1 | vulnerable |
| bookworm (security) | 10.42-1+deb12u1 | vulnerable |
| trixie | 10.46-1~deb13u2 | vulnerable |
| trixie (security) | 10.46-1~deb13u3 | fixed |
| forky | 10.48-3 | vulnerable |
| sid | 10.48-3.1 | fixed |
The information below is based on the following data on fixed versions.
Notes
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m
Fixed by: https://github.com/PCRE2Project/pcre2/commit/2b4038298072684b0fae29b15bedfb1a75bda46d (pcre2-10.49)