#1146405 trixie-pu: package pcre2/10.46-1~deb13u2

#1146405#5
Date:
2026-09-01 12:38:07 UTC
From:
To:
Hi,

The recent 10.48 release of PCRE2 included a number of security
fixes. Upstream provided backported fixes for 10.46 (the version in
trixie), and the security team think this doesn't warrant a DSA but
would be good to go out in the forthcoming trixie point release, cf:

https://security-tracker.debian.org/tracker/source-package/pcre2

These are fixes provided (and tested) by upstream. The compile-time
tests pass, and I'm additionally getting debusine to run the
autopkgtests of the immediate reverse-dependencies:

https://debusine.debian.net/debian/developers/work-request/1209574/

I attach a source debdiff; it's quite lengthy because it's 11
backported fixes, which you can see separately in the upstream branch:

https://github.com/PCRE2Project/pcre2/compare/main...release/pcre2-10.46

Thanks,

Matthew

#1146405#12
Date:
2026-09-04 11:25:56 UTC
From:
To:
package release.debian.org
tags 1146405 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: pcre2
Version: 10.46-1~deb13u2

Explanation: fix several out of bounds access issues

#1146405#17
Date:
2026-09-04 11:25:56 UTC
From:
To:
package release.debian.org
tags 1146405 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: pcre2
Version: 10.46-1~deb13u2

Explanation: fix several out of bounds access issues

#1146405#22
Date:
2026-09-12 08:05:41 UTC
From:
To:
This update was released as part of 13.7.