From https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m: | A regular expression can cause JIT-compiled matching to write outside | the maximum memory area of a growable JIT stack. A sufficiently large | single stack allocation may exceed the fixed amount by which the stack | is grown, allowing subsequent writes below the allocated region. | | An attacker must be able to supply a regular expression that is JIT | compiled and matched by an application using a growable JIT stack. | Patterns with very large numbers of capturing groups can trigger | the issue. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of pcre2, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1149217@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Salvatore Bonaccorso <carnil@debian.org> (supplier of updated pcre2 package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Mon, 28 Sep 2026 16:04:18 +0200 Source: pcre2 Architecture: source Version: 10.48-3.1 Distribution: unstable Urgency: medium Maintainer: Matthew Vernon <matthew@debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 1149217 Changes: pcre2 (10.48-3.1) unstable; urgency=medium . * Non-maintainer upload. * GHSA-r9hj-j2rw-4q3m: Fix large JIT stack allocation (Closes: #1149217) * For release, revert platform-specific test case Checksums-Sha1: 8e3802b146d72f8d7932e4ae1008238eca67fb5a 2371 pcre2_10.48-3.1.dsc 0dd891adfe8e4ecb677bf086b8e418c54f0fad15 8827 pcre2_10.48-3.1.diff.gz 9c4becfe39cc337ebd84c39d0297a6b41df411a6 5243 pcre2_10.48-3.1_source.buildinfo Checksums-Sha256: ab7b0676f36cd9de83e812c800873e53605c09bacad7dc2c203aa7222ac9ab68 2371 pcre2_10.48-3.1.dsc 34420b40e5c1277c4d847ab2b4f54dd58bf8ad63bf5f3995378de73295c788a9 8827 pcre2_10.48-3.1.diff.gz 481b710f633923df85aaf4dad3b928de70e246804346f67dafd7c81ce5484095 5243 pcre2_10.48-3.1_source.buildinfo Files: 38dcbf1cc91dc45777a9f5a215686ee5 2371 libs optional pcre2_10.48-3.1.dsc 4e53e00b5ddf345885f469fd252efb30 8827 libs optional pcre2_10.48-3.1.diff.gz 2fbdb2533ac2c1a46a3ddc06d447c93f 5243 libs optional pcre2_10.48-3.1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmq6jVBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EN0UP/RYTc/gGAl3d4K+5v6qDCPKSzxnnHv63 T0e86OQ8DrPmio8fLPL/E8P/OlpFST3dhTLmso+Cd1mPh2GV8qZf0Ulp6aCC4d5t 1DtUFrV5WUVKYYhrXBcRQgf85axb1fQnRFLHYu7J/ivZX4UN3xcIHDhIR34M27+/ NjppraPdoAp6JbQUfuZ50bZVg6MlKAfVx6UMqzRjVcehD+vOBTxdyps6kMzZM2qt TOvh1NLGPK60BGWW9ZNmYvw0Sjm8DlNLWFEekw/+G0d8SVjLj6qZp58gomrs6izu NlPyCFkmeGcr9hKyXVQcXaYd7FoM49VJum1HeuYrBNJq/K3G1d6rKHDuEwAGc6/u Ydk1GlkG6AEPGcisQLg1sEmiyySHZyf7RvVIOyn+hNKzxhK9+AnpdqzJo2BRGMha uUhoIpkghrh7lnJdk3BBT8XVKkyPe6I2K00/DVxR2CYJHS337nyYWYw8e6qAWs5W f5wuzsh5rg+3Q070SQYNb3cg9tKpWSxtr0wf8ejQSWVRYwW2I5meBGAzFT4nCUxK N6CaarDwERdVjH+vc0B3z24m0xHs+32l+1QrAE0zSUvPvQeI4oHWGaPTB0ME96Hw TTlxn+RiT0Kpq1hAKb/K46p/swtXu31yJRLt99zMeJWGvPJIWI2CYZ1KLbGDRozB /b8Pl+3uxyMx =cJKd -----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of pcre2, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1149217@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Salvatore Bonaccorso <carnil@debian.org> (supplier of updated pcre2 package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Mon, 28 Sep 2026 16:07:53 +0200 Source: pcre2 Architecture: source Version: 10.46-1~deb13u3 Distribution: trixie-security Urgency: high Maintainer: Matthew Vernon <matthew@debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 1149217 Changes: pcre2 (10.46-1~deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * GHSA-r9hj-j2rw-4q3m: Fix large JIT stack allocation (Closes: #1149217) * For release, revert platform-specific test case Checksums-Sha1: e5fb135d6cf0465aa05ebdd5b5e72c3eb700a52b 2406 pcre2_10.46-1~deb13u3.dsc 6858f0eb287c8285f53a038c8a95dc43ba51c653 2718545 pcre2_10.46.orig.tar.gz 205a17397d764e25a8b4e86af9d70263e74eff66 20405 pcre2_10.46-1~deb13u3.diff.gz 0f674c754660d0d8b46cefcfe575cd1b8d618303 5267 pcre2_10.46-1~deb13u3_source.buildinfo Checksums-Sha256: 5f317534eff1e33f0a5690a866ba2f2c9399c60ce9b74c89039d4de372420c5c 2406 pcre2_10.46-1~deb13u3.dsc 8d28d7f2c3b970c3a4bf3776bcbb5adfc923183ce74bc8df1ebaad8c1985bd07 2718545 pcre2_10.46.orig.tar.gz 28734c85365f431a4494c2efe2cdb42ed432673f962e421826f3c3b7aa76c4cf 20405 pcre2_10.46-1~deb13u3.diff.gz 00359561d93adb969da4927c654e4a62f3400cfa878576526ca5abdcb3a08598 5267 pcre2_10.46-1~deb13u3_source.buildinfo Files: 5a566c4a169db25ad54e962c7ee66cb3 2406 libs optional pcre2_10.46-1~deb13u3.dsc 38c1d3820b744afbc0565144ef893129 2718545 libs optional pcre2_10.46.orig.tar.gz 8699de04c420b7db51ec1cc87b4e7fa9 20405 libs optional pcre2_10.46-1~deb13u3.diff.gz 255f63ecea1c50843c053c374c745537 5267 libs optional pcre2_10.46-1~deb13u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmq7OwNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EtfUP/jDEOmdy1jeovPPCF+QQTsYjtmT0ISS9 7RPDDQbrHWpKBBP+wSNbzcdUNhLDcnyuRd73CKZZio5/ELOVESzCc7LVhmgu86eO /MfsQ4BG/VqgCHIO+gy7HgNQW5AUlixsYJkQo45xT/sHVRS3jlIstaw2xd/3k1NU ZnT+TzXGhDbxpoxsQFEMjCi+AgZqsbAuSs4gfnvMv4kZu09CN4KwvYBySJi3PnbI 1TE55vJOwtcEzmay9GlRX5z/fBpLEgwtixEFQRkH92YEdaBcDv5P/JyhK/3uSL74 6wGXuNEcXNoSkfraXkKM2Drl5HHF7bsdyiqplByYMt5kCItUE1Y/BL/WzFIFTFNs O+JO/My1XVYnXfe62r7KNfNJVoOJqMkVT8+TBjyEFXxFzDSUQsQ1KtglqCP6HOYj auPkTn6Y/ZFTEJUQOUCzwzrhJ+sEDr55+ZHPV+DKB58814gBabmckNkZoBwDNVSa u0zDX+IAURdJ/bZQu3e5PF2iZjxSGWGyFU0NqPyEJ9UnFQHHf5M90QQUxHFG7swb I9KWPKSJOKFsxcguKVnGxcnN9OxmbL2aW2g/PLKfjzUCOjQD1f5h2XsXOF1UkMIp Rvxaps6cMgdzpaQV/AJlrviqWOANZRp3yhPJDsT26LZxNWpizMYV8V6vipf9iL6f lJ1eWaBifcYB =rU4B -----END PGP SIGNATURE-----