[CLSA-2026:1790931264] Fix CVE(s): CVE-2026-103111
Type:
security
Severity:
Important
Release date:
2026-10-02 08:54:48 UTC
Description:
* Update to 10.49 * Rename the Debian source package from pcre2 to alt-pcre2 so it matches the binary package names and the other alt-* libraries (alt-pcre, alt-sqlite, alt-libxml2); the orig tarball becomes alt-pcre2_.orig. * Security-only upstream release: GHSA-r9hj-j2rw-4q3m (HIGH, no CVE id yet) - out-of-bounds write in JIT matching with a growable JIT stack and a pattern needing an unusually large JIT stack. Sonames unchanged (libpcre2-8/16/32.so.0, libpcre2-posix.so.3).
CVEs fixed:
Updated packages:
  • alt-pcre2_10.49-1_amd64.deb
    sha:51262da34e30ac5e90509907c28d59a18e075660
  • alt-pcre2-dev_10.49-1_amd64.deb
    sha:d88516ea3e9f0f2063003e30798b180dda6fb1ad
  • alt-pcre2-static_10.49-1_amd64.deb
    sha:ba9e2db2611bbf8ce9cafee1d210d7f18982b4f5
  • alt-pcre2-tools_10.49-1_amd64.deb
    sha:09386c8286636453e2b3c9c5384ca5d223e7e252
  • alt-pcre2-utf16_10.49-1_amd64.deb
    sha:c454b4665ea08f6e69c952c5775daf52dfe4f440
  • alt-pcre2-utf32_10.49-1_amd64.deb
    sha:e11c9d244bde1941c2111141e51fa9d567605759
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.