CVE-2026-89161
MariaDB Server 脆弱性の分析と軽減

概要

CVE-2026-89161 is a memory management vulnerability in PCRE2's JIT matching engine that causes an incorrect free operation when pcre2_jit_match() is called with a match data object that previously held a copied subject (via PCRE2_COPY_MATCHED_SUBJECT from a non-JIT match). All PCRE2 versions before 10.48 are affected, including the 10.48-rc1 release candidate. The vulnerability was published on September 11, 2026, and patched in PCRE2 10.48 released August 31, 2026. It carries a CVSS v3.1 base score of 7.8 (High) per Feedly/NVD, or 7.4 (High) per ENISA (Red Hat Advisory, PCRE2 Release).

技術的な詳細

The root cause is classified under CWE-590 (Free of Memory Not on the Heap) and CWE-1341 (Multiple Releases of Same Resource or Handle). When pcre2_match() is called with PCRE2_COPY_MATCHED_SUBJECT, it stores a heap-allocated copy of the subject string in the match data object and sets the PCRE2_MD_COPIED_SUBJECT flag. If the same match data object is subsequently passed to pcre2_jit_match(), the fast-path JIT function does not properly handle this pre-existing copied subject — it neither releases the memory (causing a leak) nor clears the flag, leading to an invalid free operation when the match data is later freed. The fix, implemented in PR #937, ensures that pcre2_jit_match() correctly detects and frees any previously copied subject before proceeding (GitHub PR #937, PCRE2 Release).

影響

Successful exploitation can result in memory corruption, information disclosure (memory leak), or denial of service (crash due to invalid free). A local attacker with low privileges and no user interaction required can trigger the incorrect free by crafting an application workflow that reuses a match data object between pcre2_match() with PCRE2_COPY_MATCHED_SUBJECT and pcre2_jit_match(). Given PCRE2's widespread use as a regex library in many applications and operating system components, the vulnerability's scope extends to any software that uses the JIT fast-path matching API in this specific pattern (Red Hat Advisory, Feedly).

エクスプロイト可能性

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.11%, reflecting low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies it as non-automatable with no known exploitation (Red Hat Advisory, GitHub PR #937).

軽減策と回避策

The primary remediation is to upgrade PCRE2 to version 10.48 or later, which includes the fix merged in PR #937. Linux distribution vendors including SUSE and openSUSE have released updated packages (e.g., SUSE-SU-2026:4201-1 and SUSE-SU-2026:4241-1). Organizations should prioritize patching systems where local users have access to applications using PCRE2 with JIT compilation enabled, particularly those that reuse match data objects across JIT and non-JIT match calls. No configuration-based workaround is available other than disabling JIT compilation in PCRE2 if upgrading is not immediately possible (PCRE2 Release, SUSE Advisory).

コミュニティの反応

Red Hat has published a security advisory tracking this CVE, and SUSE issued security updates for affected packages shortly after disclosure. The oss-security mailing list carried a notification (seclists.org/oss-sec/2026/q3/723). Microsoft also acknowledged the vulnerability via its Security Response Center. Community reaction has been measured, consistent with a library-level memory management bug that requires specific API usage patterns to trigger (Red Hat Advisory, SUSE Advisory).

関連情報

Linuxディストリビューションの修正状況

主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。

Debian

修正済

bookworm

pcre2: 10.42-1+deb12u1

修正済

sid

pcre2: 10.48-1

修正済

trixie

pcre2: 10.46-1~deb13u2

修正済

Ubuntu

不明

bionic (esm-apps)

pcre2

不明

devel

pcre2

不明

focal (esm-infra)

pcre2

不明

jammy

pcre2

不明

noble

pcre2

不明

resolute

pcre2

不明

xenial (esm-apps-legacy)

pcre2

不明

RHEL / CentOS

影響

OpenShift

openshift/ose-rhel-coreos-8

影響

RHEL 8

mariadb:10.11/mariadb.src

影響

RHEL 9

bootc.src

影響

RHEL 10

mariadb10.11.src

影響

Alpine

影響

edge

10.40-r0

影響

v3.19

10.40-r0

影響

v3.20

10.40-r0

影響

v3.21

10.40-r0

影響

v3.22

10.40-r0

影響

v3.23

10.47-r0

影響

v3.24

10.47-r1

影響

ソースこのレポートは AI を使用して生成されました

関連 MariaDB Server 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-89161HIGH7.8
  • MariaDB Server logoMariaDB Server
  • mariadb-embedded
いいえはいSep 11, 2026
CVE-2026-89157HIGH7.4
  • MariaDB Server logoMariaDB Server
  • mariadb-oqgraph-engine
いいえはいSep 11, 2026
CVE-2026-89160MEDIUM6.5
  • MariaDB Server logoMariaDB Server
  • system-reinstall-bootc
いいえはいSep 11, 2026
CVE-2026-89158MEDIUM6.5
  • MariaDB Server logoMariaDB Server
  • mariadb:11.8::mariadb-server-galera
いいえはいSep 11, 2026
CVE-2026-89162LOW3.3
  • MariaDB Server logoMariaDB Server
  • Judy
いいえはいSep 11, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者