CVE-2026-89156:
MariaDB Server Análisis y mitigación de vulnerabilidades
Vista general
CVE-2026-89156 is an out-of-bounds read vulnerability in the PCRE2 library's pcre2_match() function that occurs after a JIT fallback when invalid UTF data is supplied as input. It affects PCRE2 versions 10.34 through 10.47 (8-bit code-unit width) and was fixed in version 10.48, released August 31, 2026. The vulnerability was publicly disclosed on September 11, 2026, and reported by Albert Zhang. It carries a CVSS v3.1 base score of 5.9 (Medium) per Feedly/NVD, though the GitHub Security Advisory assigns a lower score of 2.9 (Low) using a local attack vector (PCRE2 Advisory, PCRE2 Release).
Técnicas
The root cause (CWE-125: Out-of-bounds Read) lies in an inconsistency between the lookbehind boundary used by the JIT validation block and the one used by the interpreter fallback path. When pcre2_jit_compile() is called for one matching mode (e.g., PCRE2_JIT_COMPLETE) and pcre2_match() is subsequently called with a different mode (e.g., PCRE2_PARTIAL_SOFT), JIT returns PCRE2_ERROR_JIT_BADOPTION and falls back to the interpreter. The JIT block had already validated only a narrow region of the subject buffer (rewinding start_match by max_lookbehind), set jit_checked_utf = TRUE, and returned. The interpreter then skips its own UTF validation but sets mb->check_subject = subject (offset 0) instead of the JIT-rewound start_match, breaking the lookbehind floor invariant. During OP_UCP_WORD_BOUNDARY evaluation, the guard Feptr == mb->check_subject evaluates false, allowing a backward scan into unvalidated memory. The GETUTF8 macro decodes the invalid 0xFF lead byte as a 6-byte sequence, producing fc = 0x40000000 — far exceeding MAX_UTF_CODE_POINT — which is then used as an index into ucd_stage1[], reading ~16 MB past the table boundary and causing a deterministic SIGSEGV. A complete PoC reproducer is included in the GitHub Security Advisory (PCRE2 Advisory).
Impacto
Successful exploitation causes a deterministic process crash (SIGSEGV, exit 139) in any application that uses pcre2_match() with attacker-controlled subject data under the specific vulnerable option combination, resulting in denial of service. The advisory confirms no information disclosure or integrity impact has been demonstrated; the out-of-bounds read produces a wild table index that crashes the process before any data can be meaningfully exfiltrated. The vulnerability is standalone and not chainable to privilege escalation or code execution (PCRE2 Advisory).
Explotabilidad
A complete, runnable C PoC that crashes the process 10/10 times in a standard -O2 build (no sanitizer required) is publicly available in the GitHub Security Advisory. The EPSS score is 0.00102 (approximately 0.1%), indicating low probability of widespread exploitation. There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a specific and unusual API usage pattern (JIT compiled for one mode, match attempted in another), limiting the realistic attack surface (PCRE2 Advisory).
Pasos de explotación
- Identify a vulnerable target: Find a network-exposed application using PCRE2 versions 10.34–10.47 (8-bit) with UTF and JIT support enabled, where the application passes attacker-controlled input to
pcre2_match()without thePCRE2_NO_UTF_CHECKflag. - Confirm vulnerable API usage: Verify (via source review, fuzzing, or behavioral testing) that the application compiles patterns with
PCRE2_UTF | PCRE2_UCP, JIT-compiles forPCRE2_JIT_COMPLETEonly, and callspcre2_match()withPCRE2_PARTIAL_SOFT(or another mode not JIT-compiled), a non-zerostartoffset, and a pattern containing a lookbehind (e.g.,\b). - Craft malicious subject buffer: Construct an input buffer containing an invalid UTF-8 byte (e.g.,
0xFF) near the end, with astartoffsetpointing close to the buffer boundary (e.g., offset 84 in an 85-byte buffer), so the JIT-rewoundstart_matchplaces the lookbehind scan over the invalid byte at offset 82. - Submit the payload: Send the crafted input to the application through its normal input channel (e.g., HTTP request body, search field, API parameter).
- Trigger the crash: The JIT block validates only
[83, 85), setsjit_checked_utf = TRUE, and falls back to the interpreter. The interpreter skips validation, theOP_UCP_WORD_BOUNDARYhandler scans back to the0xFFbyte,GETUTF8decodes it asfc = 0x40000000, andUCD_CHARTYPE(fc)dereferences ~16 MB pastucd_stage1[], causing SIGSEGV and crashing the process (PCRE2 Advisory).
Indicadores de compromiso
- Network: Repeated requests to application endpoints that accept regex-matched input, containing binary or non-UTF-8 data (e.g.,
0xFF,0xFEbytes) near the end of the payload with a high starting offset parameter. - Logs: Application crash logs or core dumps referencing
pcre2_matchorsrc/pcre2_match.cat lines around theOP_UCP_WORD_BOUNDARYhandler; segmentation fault signals (SIGSEGV, exit code 139) in process logs. - Process: Unexpected termination of application processes that perform regex matching; repeated process restarts by a supervisor (e.g., systemd, Docker restart policy) following SIGSEGV.
- File System: Core dump files (
core.*) generated by the application process, potentially containing subject buffer contents if core dumps are enabled (PCRE2 Advisory).
Mitigación y soluciones alternativas
Upgrade PCRE2 to version 10.48 or later, which fixes the issue by checking that JIT supports the requested matching mode before entering the JIT validation path (fix commit: f67db227af31bba7cdf2a7a00b97af91b588c2f5). If immediate patching is not possible, the following workarounds apply: (1) compile the pattern for all JIT matching modes that will be used (e.g., compile both PCRE2_JIT_COMPLETE and PCRE2_JIT_PARTIAL_SOFT); (2) pass PCRE2_NO_JIT to disable JIT for affected calls; or (3) validate the subject as valid UTF-8 before calling pcre2_match(). Do not use PCRE2_NO_UTF_CHECK as a workaround, as this removes the caller's entitlement to a safe error return (PCRE2 Advisory, PCRE2 Release).
Reacciones de la comunidad
The vulnerability was reported by Albert Zhang and credited to Cristian Cadar as a secondary contact in the GitHub Security Advisory. The PCRE2 maintainer (NWilson) published the advisory and fix on August 31, 2026, alongside the 10.48 release, which also addressed five other security issues. SUSE issued a security update (SUSE-SU-2026:4201-1) incorporating the fix, and the issue was discussed on the oss-security mailing list. No significant broader media coverage or social media controversy has been identified (PCRE2 Advisory, PCRE2 Release).
Recursos adicionales
Estado de corrección de la distribución Linux
Arreglar la disponibilidad en las principales distribuciones de Linux y sus lanzamientos.
bookworm
pcre2: 10.42-1+deb12u1
sid
pcre2: 10.48-1
trixie
pcre2: 10.46-1~deb13u2
bionic (esm-apps)
pcre2
devel
pcre2
focal (esm-infra)
pcre2
jammy
pcre2
noble
pcre2
resolute
pcre2
xenial (esm-apps-legacy)
pcre2
OpenShift
openshift/ose-rhel-coreos-8
RHEL 8
mariadb:10.11/mariadb.src
RHEL 9
bootc.src
RHEL 10
mariadb10.11.src
Fuente: Este informe se generó utilizando IA
Relacionado MariaDB Server Vulnerabilidades:
Evaluación gratuita de vulnerabilidades
Compare su postura de seguridad en la nube
Evalúe sus prácticas de seguridad en la nube en 9 dominios de seguridad para comparar su nivel de riesgo e identificar brechas en sus defensas.
Recursos adicionales de Wiz
Obtén una demostración personalizada
¿Listo para ver a Wiz en acción?
"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."