erlang vendors a copy of pcre2 at: erts/emulator/pcre/pcre2_substring.c This copy predates commit 8156b39 (August 9, 2026) which fixes an integer overflow in pcre2_substring.c and pcre2_convert.c. The fix adds an overflow guard: if (size > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1)) - 1) return PCRE2_ERROR_NOMEMORY; Note: the canonical Debian pcre2 package (10.46-1) also does not yet contain this fix. No CVE has been assigned yet. The fix is public at: https://github.com/PCRE2Project/pcre2/commit/8156b39 Please update the bundled pcre2 to the latest upstream version. Found by: Attack of the Clones GSoC 2026 pipeline (salsa.debian.org/rouca/gsoc2026) Gajendra Nath Soren gajendranath025@gmail.com