[CLSA-2026:1790941916] alt-pcre2: Fix of CVE-2026-103111
Type:
security
Severity:
Important
Release date:
2026-10-02 11:52:11 UTC
Description:
- Update to 10.49 - Security-only upstream release: GHSA-r9hj-j2rw-4q3m (HIGH, no CVE id yet) - out-of-bounds write in JIT matching when a growable JIT stack (pcre2_jit_stack_create/pcre2_jit_stack_assign) is used with a pattern that needs an unusually large JIT stack, e.g. very many capturing groups; only src/pcre2_jit_compile.c changes. Library versions 16:1:16 / posix 3:9:0 are revision-only bumps, so libpcre2-8/16/32.so.0 and libpcre2-posix.so.3 keep their sonames and no dependent rebuild is needed.
CVEs fixed:
Updated packages:
  • alt-pcre2-10.49-1.el8.x86_64.rpm
    sha:4701a34bda619f8fa8655cafb6ae2d71f9aa364453f645ed972606aa60302577
  • alt-pcre2-devel-10.49-1.el8.x86_64.rpm
    sha:52d473ae6b3ab1ee50fa72950f1d0240df6aa0141cf419f080cfbd50faea12da
  • alt-pcre2-static-10.49-1.el8.x86_64.rpm
    sha:083dd148a50471d72ef09891f5cf7fab633090472b2f78b9b8f2bd2d4f53cfa5
  • alt-pcre2-tools-10.49-1.el8.x86_64.rpm
    sha:3da9aa1496d0fc13c8340492ce4a4eb6dc24c852d8109607f8935bca28a3e577
  • alt-pcre2-utf16-10.49-1.el8.x86_64.rpm
    sha:8b7251a5ff97e5eafbb4041b55df70a835001a06236b7e0f87cc69a2292aaf86
  • alt-pcre2-utf32-10.49-1.el8.x86_64.rpm
    sha:65254cff133e017c0c29c69576a65d32120aedb0133a9a86127de1948ee0c3e5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.