
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-89161 is a memory management vulnerability in PCRE2's JIT matching engine that causes an incorrect free operation when pcre2_jit_match() is called with a match data object that previously held a copied subject (via PCRE2_COPY_MATCHED_SUBJECT from a non-JIT match). All PCRE2 versions before 10.48 are affected, including the 10.48-rc1 release candidate. The vulnerability was published on September 11, 2026, and patched in PCRE2 10.48 released August 31, 2026. It carries a CVSS v3.1 base score of 7.8 (High) per Feedly/NVD, or 7.4 (High) per ENISA (Red Hat Advisory, PCRE2 Release).
The root cause is classified under CWE-590 (Free of Memory Not on the Heap) and CWE-1341 (Multiple Releases of Same Resource or Handle). When pcre2_match() is called with PCRE2_COPY_MATCHED_SUBJECT, it stores a heap-allocated copy of the subject string in the match data object and sets the PCRE2_MD_COPIED_SUBJECT flag. If the same match data object is subsequently passed to pcre2_jit_match(), the fast-path JIT function does not properly handle this pre-existing copied subject — it neither releases the memory (causing a leak) nor clears the flag, leading to an invalid free operation when the match data is later freed. The fix, implemented in PR #937, ensures that pcre2_jit_match() correctly detects and frees any previously copied subject before proceeding (GitHub PR #937, PCRE2 Release).
Successful exploitation can result in memory corruption, information disclosure (memory leak), or denial of service (crash due to invalid free). A local attacker with low privileges and no user interaction required can trigger the incorrect free by crafting an application workflow that reuses a match data object between pcre2_match() with PCRE2_COPY_MATCHED_SUBJECT and pcre2_jit_match(). Given PCRE2's widespread use as a regex library in many applications and operating system components, the vulnerability's scope extends to any software that uses the JIT fast-path matching API in this specific pattern (Red Hat Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.11%, reflecting low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies it as non-automatable with no known exploitation (Red Hat Advisory, GitHub PR #937).
The primary remediation is to upgrade PCRE2 to version 10.48 or later, which includes the fix merged in PR #937. Linux distribution vendors including SUSE and openSUSE have released updated packages (e.g., SUSE-SU-2026:4201-1 and SUSE-SU-2026:4241-1). Organizations should prioritize patching systems where local users have access to applications using PCRE2 with JIT compilation enabled, particularly those that reuse match data objects across JIT and non-JIT match calls. No configuration-based workaround is available other than disabling JIT compilation in PCRE2 if upgrading is not immediately possible (PCRE2 Release, SUSE Advisory).
Red Hat has published a security advisory tracking this CVE, and SUSE issued security updates for affected packages shortly after disclosure. The oss-security mailing list carried a notification (seclists.org/oss-sec/2026/q3/723). Microsoft also acknowledged the vulnerability via its Security Response Center. Community reaction has been measured, consistent with a library-level memory management bug that requires specific API usage patterns to trigger (Red Hat Advisory, SUSE Advisory).
主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。
bionic (esm-apps)
pcre2
devel
pcre2
focal (esm-infra)
pcre2
jammy
pcre2
noble
pcre2
resolute
pcre2
xenial (esm-apps-legacy)
pcre2
OpenShift
openshift/ose-rhel-coreos-8
RHEL 8
mariadb:10.11/mariadb.src
RHEL 9
bootc.src
RHEL 10
mariadb10.11.src
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"