{"id":"SUSE-SU-2026:23740-1","summary":"Security update for pcre2","details":"This update for pcre2 fixes the following issues:\n\n- CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893).\n- CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054).\n- CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053).\n- CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052).\n- CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject\n  (bsc#1280051).\n- CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match`\n  (bsc#1280050).\n","modified":"2026-09-27T18:23:09.758503092Z","published":"2026-09-15T07:32:27Z","related":["CVE-2026-86145","CVE-2026-89156","CVE-2026-89157","CVE-2026-89158","CVE-2026-89160","CVE-2026-89161"],"upstream":["CVE-2026-86145","CVE-2026-89156","CVE-2026-89157","CVE-2026-89158","CVE-2026-89160","CVE-2026-89161"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623740-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277707"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277708"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277709"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277713"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279893"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280050"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280051"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280054"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-86145"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89156"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89157"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89158"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89160"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89161"}],"affected":[{"package":{"name":"pcre2","ecosystem":"SUSE:Linux Micro 6.1","purl":"pkg:rpm/suse/pcre2&distro=SUSE%20Linux%20Micro%206.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.42-slfo.1.1_2.1"}]}],"ecosystem_specific":{"binaries":[{"libpcre2-8-0":"10.42-slfo.1.1_2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23740-1.json"}}],"schema_version":"1.9.0"}