{"id":"SUSE-SU-2026:23906-1","summary":"Security update for pcre2","details":"This update for pcre2 fixes the following issues:\n\n- CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893).\n- CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054).\n- CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053).\n- CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052).\n- CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject\n  (bsc#1280051).\n- CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match`\n  (bsc#1280050).\n- CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049).\n","modified":"2026-09-30T18:23:12.229789994Z","published":"2026-09-23T19:42:24Z","related":["CVE-2026-86145","CVE-2026-89156","CVE-2026-89157","CVE-2026-89158","CVE-2026-89160","CVE-2026-89161","CVE-2026-89162"],"upstream":["CVE-2026-86145","CVE-2026-89156","CVE-2026-89157","CVE-2026-89158","CVE-2026-89160","CVE-2026-89161","CVE-2026-89162"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623906-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277707"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277708"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277709"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277712"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277713"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279893"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280049"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280050"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280051"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280054"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-86145"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89156"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89157"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89158"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89160"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89161"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89162"}],"affected":[{"package":{"name":"pcre2","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/pcre2&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.45-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"libpcre2-16-0":"10.45-160000.4.1","libpcre2-32-0":"10.45-160000.4.1","libpcre2-8-0":"10.45-160000.4.1","libpcre2-posix3":"10.45-160000.4.1","pcre2-devel":"10.45-160000.4.1","pcre2-devel-static":"10.45-160000.4.1","pcre2-doc":"10.45-160000.4.1","pcre2-tools":"10.45-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23906-1.json"}},{"package":{"name":"pcre2","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/pcre2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.45-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"libpcre2-16-0":"10.45-160000.4.1","libpcre2-32-0":"10.45-160000.4.1","libpcre2-8-0":"10.45-160000.4.1","libpcre2-posix3":"10.45-160000.4.1","pcre2-devel":"10.45-160000.4.1","pcre2-devel-static":"10.45-160000.4.1","pcre2-doc":"10.45-160000.4.1","pcre2-tools":"10.45-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23906-1.json"}}],"schema_version":"1.9.0"}