[CLSA-2026:1790937243] Fix CVE(s): CVE-2026-103111
Type:
security
Severity:
Important
Release date:
2026-10-02 10:34:34 UTC
Description:
* Update to 10.49 * Rename the Debian source package from pcre2 to alt-pcre2 so it matches the binary package names and the other alt-* libraries (alt-pcre, alt-sqlite, alt-libxml2); the orig tarball becomes alt-pcre2_.orig. * Security-only upstream release: GHSA-r9hj-j2rw-4q3m (HIGH, no CVE id yet) - out-of-bounds write in JIT matching with a growable JIT stack and a pattern needing an unusually large JIT stack. Sonames unchanged (libpcre2-8/16/32.so.0, libpcre2-posix.so.3).
CVEs fixed:
Updated packages:
  • alt-pcre2_10.49-1_amd64.deb
    sha:068047c328518b0c77134b4f15034668bca423b1
  • alt-pcre2-dev_10.49-1_amd64.deb
    sha:dfcc33d01f9d52d7d38db1a9e430a896c14bbf47
  • alt-pcre2-static_10.49-1_amd64.deb
    sha:9f0ab3c0d55c1914335341e97b1f941074798129
  • alt-pcre2-tools_10.49-1_amd64.deb
    sha:756f8754083d5444e1af69e1605bbbd05d248a7b
  • alt-pcre2-utf16_10.49-1_amd64.deb
    sha:1b10c54ec6eed08b1bd94c39b900fb84a2138c31
  • alt-pcre2-utf32_10.49-1_amd64.deb
    sha:f2f5b745f8f81c48e931ee0a349ff9f74a215f1a
  • alt-pcre2_10.49-1_arm64.deb
    sha:a0748742c78e847b790ba655ffae1e88d2c0a0fe
  • alt-pcre2-dev_10.49-1_arm64.deb
    sha:b3364a48c25eed5d0b3b7d3ebb22a1e7d00af165
  • alt-pcre2-static_10.49-1_arm64.deb
    sha:d8d194ee599900168b11fbb47cf6f73aaace96b7
  • alt-pcre2-tools_10.49-1_arm64.deb
    sha:6094190761e36dc4174a82781759e8fe1e50a092
  • alt-pcre2-utf16_10.49-1_arm64.deb
    sha:ae7f6e51f759647b319834aa529b25dfeb0a980c
  • alt-pcre2-utf32_10.49-1_arm64.deb
    sha:ce8e72987e87dec4b9a77b791f8ca4a9f9a74e53
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.