[CLSA-2026:1790921895] Fix CVE(s): CVE-2026-103111
Type:
security
Severity:
Important
Release date:
2026-10-02 06:18:26 UTC
Description:
* Update to 10.49 * Rename the Debian source package from pcre2 to alt-pcre2 so it matches the binary package names and the other alt-* libraries (alt-pcre, alt-sqlite, alt-libxml2); the orig tarball becomes alt-pcre2_.orig. * Security-only upstream release: GHSA-r9hj-j2rw-4q3m (HIGH, no CVE id yet) - out-of-bounds write in JIT matching with a growable JIT stack and a pattern needing an unusually large JIT stack. Sonames unchanged (libpcre2-8/16/32.so.0, libpcre2-posix.so.3).
CVEs fixed:
Updated packages:
  • alt-pcre2_10.49-1_amd64.deb
    sha:7314f293f32e54b8d463b1a74669566c6a4b78c1
  • alt-pcre2-dev_10.49-1_amd64.deb
    sha:d88516ea3e9f0f2063003e30798b180dda6fb1ad
  • alt-pcre2-static_10.49-1_amd64.deb
    sha:358cc0380c1804b3d71b93cc579f674018de6cb2
  • alt-pcre2-tools_10.49-1_amd64.deb
    sha:522c1d23d3ceea9158c0be9ea3ae14fb71e17513
  • alt-pcre2-utf16_10.49-1_amd64.deb
    sha:3bb8df7038568b195d6fa585ac449f44f97d8f2c
  • alt-pcre2-utf32_10.49-1_amd64.deb
    sha:788f95a8201fca83f2ac4f74559624b1ea92643f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.