[CLSA-2026:1790942121] alt-pcre2: Fix of CVE-2026-103111
Type:
security
Severity:
Important
Release date:
2026-10-02 11:55:36 UTC
Description:
- Update to 10.49 - Security-only upstream release: GHSA-r9hj-j2rw-4q3m (HIGH, no CVE id yet) - out-of-bounds write in JIT matching when a growable JIT stack (pcre2_jit_stack_create/pcre2_jit_stack_assign) is used with a pattern that needs an unusually large JIT stack, e.g. very many capturing groups; only src/pcre2_jit_compile.c changes. Library versions 16:1:16 / posix 3:9:0 are revision-only bumps, so libpcre2-8/16/32.so.0 and libpcre2-posix.so.3 keep their sonames and no dependent rebuild is needed.
CVEs fixed:
Updated packages:
  • alt-pcre2-10.49-1.el7.x86_64.rpm
    sha:a3bc8defe561730140f7a86c8ec494c7f5a4fa36d911f1eb9832599cff2131ac
  • alt-pcre2-devel-10.49-1.el7.x86_64.rpm
    sha:9256aee206a92eab9b93b910ceed93fedc99e62e1ad5227a0d2367eab9fc5f63
  • alt-pcre2-static-10.49-1.el7.x86_64.rpm
    sha:ac3b8643f1a2e57599b5a4e01c852f9da934277c882fca854403b798da4b4f4d
  • alt-pcre2-tools-10.49-1.el7.x86_64.rpm
    sha:32a7446b7d3435cae1887e821aa662129d0b34b8cffe51d978d4ec2abdbf15a5
  • alt-pcre2-utf16-10.49-1.el7.x86_64.rpm
    sha:72f202cbeb34a16c61a206d21a2acf699c182acc4d32df47bbfd8798b9ca6f29
  • alt-pcre2-utf32-10.49-1.el7.x86_64.rpm
    sha:a52e9971d59f23d537036c7ed8aa0ebb1602a69dea6d56cbd1c5d79e426b94c3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.