[CLSA-2026:1790941724] Fix CVE(s): CVE-2026-103111
Type:
security
Severity:
Important
Release date:
2026-10-02 11:49:01 UTC
Description:
* Update to 10.49 * Rename the Debian source package from pcre2 to alt-pcre2 so it matches the binary package names and the other alt-* libraries (alt-pcre, alt-sqlite, alt-libxml2); the orig tarball becomes alt-pcre2_.orig. * Security-only upstream release: GHSA-r9hj-j2rw-4q3m (HIGH, no CVE id yet) - out-of-bounds write in JIT matching with a growable JIT stack and a pattern needing an unusually large JIT stack. Sonames unchanged (libpcre2-8/16/32.so.0, libpcre2-posix.so.3).
CVEs fixed:
Updated packages:
  • alt-pcre2_10.49-1_amd64.deb
    sha:1eeb503abb89aef1b4fc3ca7b6af2c5a25dac36d
  • alt-pcre2-dev_10.49-1_amd64.deb
    sha:dfcc33d01f9d52d7d38db1a9e430a896c14bbf47
  • alt-pcre2-static_10.49-1_amd64.deb
    sha:8affcfb5ee5085677dce19b417d08324b9e49158
  • alt-pcre2-tools_10.49-1_amd64.deb
    sha:a544fd5b2126b32d038fce9878a764ceac9cd821
  • alt-pcre2-utf16_10.49-1_amd64.deb
    sha:d783acd4f7e72743ca9244f2c9a6537b75661be9
  • alt-pcre2-utf32_10.49-1_amd64.deb
    sha:bde5c0a608162589432a16010c8c4f634f1c47f1
  • alt-pcre2_10.49-1_arm64.deb
    sha:c62ceb2f099be0b1639cce436d21848c21681c0f
  • alt-pcre2-dev_10.49-1_arm64.deb
    sha:b3364a48c25eed5d0b3b7d3ebb22a1e7d00af165
  • alt-pcre2-static_10.49-1_arm64.deb
    sha:ebc9c7da85af5de6c4541eedab9e2061f8daae36
  • alt-pcre2-tools_10.49-1_arm64.deb
    sha:0ba174ffd004857ac7923ed4ae073e2f8969f77a
  • alt-pcre2-utf16_10.49-1_arm64.deb
    sha:ca368268c5b559af9052c2e7921e2711fcd98eb8
  • alt-pcre2-utf32_10.49-1_arm64.deb
    sha:e4678c202cdf3f1d4df05df4fac536337bfa240b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.