Executive brief
PCRE2 is a widely-used regular expression pattern-matching library embedded in many applications and systems. On 32-bit platforms, a flaw in the 32-bit code-unit variant of the library allows an attacker who can provide untrusted regex patterns to trigger a buffer overflow during pattern compilation, potentially enabling code execution or system compromise.
Technical details
The vulnerability is an integer overflow in the pcre2_compile_32() function on 32-bit systems. When compiling a pattern whose compiled form requires exactly 2^30 code units, the CU2BYTES() macro wraps around, causing undersized heap buffer allocation. The attacker-controlled pattern is then compiled into the undersized buffer, resulting in an out-of-bounds heap write. The flaw only affects the 32-bit code-unit API (pcre2_compile_32) on 32-bit platforms; the 8-bit and 16-bit variants are not affected. No authentication or network access is required—only the ability to supply a crafted regex pattern to an application that uses PCRE2's 32-bit library in a 32-bit process. The vulnerability was patched in PCRE2 version 10.48 by adding bounds checks and hardening integer arithmetic in the compilation path.
Affected products
- PCRE2Project PCRE2 before 10.48
Timeline
- 2026-08-31: disclosed
- 2026-08-31: patched: Fixed in PCRE2 10.48