- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Matthew Vernon
- Date:
- 2026-09-12 08:07:46 UTC
- Severity:
- normal
- Tags:
Hi, The recent 10.48 release of PCRE2 included a number of security fixes. Upstream provided backported fixes for 10.46 (the version in trixie), and the security team think this doesn't warrant a DSA but would be good to go out in the forthcoming trixie point release, cf: https://security-tracker.debian.org/tracker/source-package/pcre2 These are fixes provided (and tested) by upstream. The compile-time tests pass, and I'm additionally getting debusine to run the autopkgtests of the immediate reverse-dependencies: https://debusine.debian.net/debian/developers/work-request/1209574/ I attach a source debdiff; it's quite lengthy because it's 11 backported fixes, which you can see separately in the upstream branch: https://github.com/PCRE2Project/pcre2/compare/main...release/pcre2-10.46 Thanks, Matthew
package release.debian.org tags 1146405 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: pcre2 Version: 10.46-1~deb13u2 Explanation: fix several out of bounds access issues
package release.debian.org tags 1146405 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: pcre2 Version: 10.46-1~deb13u2 Explanation: fix several out of bounds access issues
This update was released as part of 13.7.