CVE-2026-89160: 
MariaDB Server 취약성 분석 및 완화

개요

CVE-2026-89160 is an out-of-bounds read vulnerability in PCRE2 (Perl Compatible Regular Expressions 2) affecting versions 10.34 through 10.47 (including 10.48-rc1). The flaw exists in pcre2_match() and is triggered when matching invalid UTF subjects using the PCRE2_MATCH_INVALID_UTF flag, causing the engine to read heap memory before the start of the subject buffer. It was reported by Ilia Alshanetsky and publicly disclosed on August 31, 2026, with a fix released in PCRE2 10.48. The CVSS v3.1 base score is 6.5 (Medium) per Feedly/NVD, though the official GHSA advisory rates it 3.7 (Low) using a higher attack complexity assumption (GHSA Advisory, Red Hat).

기술적 세부 사항

The root cause is CWE-125 (Out-of-bounds Read): two backward-walking code paths in pcre2_match.c (Site A: OP_VREVERSE at line 6236) and pcre2_extuni.c (Site B: Regional Indicator count-back at line 124) use mb->start_subject as their lower bound instead of the correct mb->check_subject. Under PCRE2_MATCH_INVALID_UTF, check_subject marks the boundary between the unvalidated prefix [start_subject, check_subject) and the UTF-validated region [check_subject, end_subject). When the subject begins with a UTF-8 continuation byte (0x80–0xBF), the unbounded BACKCHAR(eptr) macro — defined as while ((*eptr & 0xc0u) == 0x80u) eptr-- — steps past start_subject and reads 1 to N bytes before the allocated heap buffer. Exploitation requires: (1) the application links libpcre2-8 or libpcre2-16; (2) patterns are compiled with both PCRE2_UTF and PCRE2_MATCH_INVALID_UTF; (3) the pattern contains variable-length lookbehind ((?<=...)) or extended grapheme matching (\X); and (4) the application accepts attacker-controlled subject strings. The 32-bit code-unit width and DFA matcher are not affected (GHSA Advisory).

영향

Successful exploitation results in a heap out-of-bounds read of 1 to N bytes of adjacent heap memory, enabling potential information disclosure of sensitive data (e.g., session tokens, cryptographic keys, or process secrets) residing in adjacent heap allocations. A secondary impact is denial of service: if the out-of-bounds read lands in an unmapped memory page, the process crashes. Integrity is not affected. The vulnerability is particularly relevant to applications that use PCRE2 with PCRE2_MATCH_INVALID_UTF for processing untrusted input, such as log scanners, HTTP request parsers, protocol matchers, and anti-spam/DLP regex engines (GHSA Advisory).

악용 가능성

Proof-of-concept (PoC) exploit code is publicly available in the GHSA advisory, consisting of two complete, standalone C programs (poc-ss001-op_vreverse.c and poc-ss002-extuni-ri.c) that compile and run against PCRE2 10.47 to demonstrate the OOB read with AddressSanitizer detection. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is 0.0022 (approximately 0.22%), indicating low probability of near-term exploitation. The vulnerability is not listed in the CISA KEV catalog. NVD SSVC classifies exploitation status as "poc" with "no" automatability (GHSA Advisory, Feedly).

착취 단계

  1. Identify target applications: Locate applications that link libpcre2-8 or libpcre2-16 and compile patterns with both PCRE2_UTF and PCRE2_MATCH_INVALID_UTF flags — common in log scanners, HTTP parsers, and protocol matchers accepting untrusted input.
  2. Craft a malicious subject string: Construct a subject string whose first byte is a UTF-8 continuation byte in the range 0x80–0xBF (e.g., 0x80), followed by content that triggers the vulnerable backward-walking code path.
  3. Target Site A (OP_VREVERSE): Submit the crafted subject to an application using a pattern with a variable-length lookbehind (e.g., (?<=a{1,2})X) compiled with PCRE2_UTF | PCRE2_MATCH_INVALID_UTF. Example subject: [0x80, 'X'].
  4. Target Site B (extuni Regional Indicator): Alternatively, submit a subject starting with 0x80 followed by two Regional Indicator codepoints (e.g., U+1F1E6 U+1F1E7) to an application using a pattern containing \X\X compiled with the same flags.
  5. Trigger OOB read: When pcre2_match() processes the subject, the backward-walk loop crosses check_subject into the unvalidated prefix, and the unbounded BACKCHAR macro decrements the pointer past start_subject, reading 1+ bytes before the allocated heap buffer.
  6. Achieve objective: The bytes read from subject[-1] onward are processed as UTF character data, potentially disclosing adjacent heap contents (information disclosure) or crashing the process if the read lands in unmapped memory (denial of service) (GHSA Advisory).

타협의 징후

  • Network: Unusual or malformed regex subject strings submitted to network-facing services that use PCRE2 for pattern matching, particularly subjects beginning with UTF-8 continuation bytes (0x80–0xBF).
  • Logs: Application crash logs or core dumps referencing pcre2_match.c (around line 6236–6243) or pcre2_extuni.c (around line 124–129); AddressSanitizer output containing heap-buffer-overflow with READ of size 1 located 1 bytes to the left of the subject buffer.
  • Process: Unexpected crashes or restarts of services that perform regex matching (e.g., log analyzers, HTTP servers, protocol parsers) without clear application-level errors; segmentation faults in processes linked against libpcre2-8.so or libpcre2-16.so.
  • File System: Core dump files generated by PCRE2-linked processes; presence of ASAN-instrumented binaries in production environments showing heap-buffer-overflow reports (GHSA Advisory).

완화 및 해결 방법

Upgrade PCRE2 to version 10.48 or later, which applies a lower buffer bound (check_subject) to prevent the two out-of-bounds reads during backward scanning through invalid UTF data. As a workaround for systems that cannot be immediately patched, avoid using PCRE2_MATCH_INVALID_UTF with untrusted subjects, or validate/sanitize all subject strings before passing them to pcre2_match(). SUSE has released a security update (SUSE-SU-2026:4201-1) for affected distributions. Microsoft has also published guidance for affected products (PCRE2 Release, GHSA Advisory, Microsoft MSRC).

커뮤니티 반응

The PCRE2 maintainer (NWilson) published the advisory and fix simultaneously with the PCRE2 10.48 release on August 31, 2026, describing it as a security fix for backward scans crossing the check_subject boundary. The reporter, Ilia Alshanetsky, provided a detailed technical report including two PoC programs and suggested CVSS scoring. SUSE issued a security update for its distributions, and the vulnerability was picked up by oss-security mailing lists and security aggregators including AusCERT and pro-linux.de. No significant social media controversy or broader community debate has been observed (GHSA Advisory, PCRE2 Release).

추가 자료

리눅스 배포판 수정 현황

주요 리눅스 배포판과 그 릴리스 전반에 걸친 가용성을 수정하세요.

Debian

수정됨

bookworm

pcre2: 10.42-1+deb12u1

수정됨

sid

pcre2: 10.48-1

수정됨

trixie

pcre2: 10.46-1~deb13u2

수정됨

Ubuntu

알 수 없음

bionic (esm-apps)

pcre2

알 수 없음

devel

pcre2

알 수 없음

focal (esm-infra)

pcre2

알 수 없음

jammy

pcre2

알 수 없음

noble

pcre2

알 수 없음

resolute

pcre2

알 수 없음

xenial (esm-apps-legacy)

pcre2

알 수 없음

RHEL / CentOS

영향을 받은 사람들

OpenShift

openshift/ose-rhel-coreos-9

영향을 받은 사람들

RHEL 8

mariadb:10.11/mariadb.src

영향을 받은 사람들

RHEL 9

mariadb:10.11/mariadb.src

영향을 받은 사람들

RHEL 10

mariadb10.11.src

영향을 받은 사람들

Alpine

영향을 받은 사람들

edge

10.40-r0

영향을 받은 사람들

v3.19

10.40-r0

영향을 받은 사람들

v3.20

10.40-r0

영향을 받은 사람들

v3.21

10.40-r0

영향을 받은 사람들

v3.22

10.40-r0

영향을 받은 사람들

v3.23

10.47-r0

영향을 받은 사람들

v3.24

10.47-r1

영향을 받은 사람들

근원: 이 보고서는 AI를 사용하여 생성되었습니다.

관련 MariaDB Server 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-89161HIGH7.8
  • MariaDB Server logoMariaDB Server
  • mariadb-server-utils
아니요예Sep 11, 2026
CVE-2026-89157HIGH7.4
  • MariaDB Server logoMariaDB Server
  • mariadb:11.8::mariadb.src
아니요예Sep 11, 2026
CVE-2026-89160MEDIUM6.5
  • MariaDB Server logoMariaDB Server
  • pcre2-static
아니요예Sep 11, 2026
CVE-2026-89158MEDIUM6.5
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-test
아니요예Sep 11, 2026
CVE-2026-89162LOW3.3
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server-utils
아니요예Sep 11, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자