Posted by Sam James on Sep 28 From https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.49 """ This is a security-only release, to address GHSA-r9hj-j2rw-4q3m. Compared to 10.48, this release has only a minimal code change to prevent an out-of-bounds write with arbitrary data. An attacker-controlled regular expression is required.
JIT buffer overflow fixed in libpcre2-10.49
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/975
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.




