Vulnerability DatabaseCVE-2026-103111

CVE-2026-103111: 
MariaDB Server vulnerability analysis and mitigation

Overview

CVE-2026-103111 is an out-of-bounds write vulnerability in PCRE2's JIT (Just-In-Time) compiler that can be triggered by an attacker-controlled regular expression when certain JIT API configurations are in use. It affects all PCRE2 versions up to and including 10.48, and is fixed in version 10.49. The vulnerability was reported by Michael Allen, with the fix developed by Zoltan Herczeg; it was publicly disclosed on September 30, 2026. It carries a CVSS v3.1 base score of 7.6 (High) (PCRE2 Advisory, Github Advisory).

Technical details

The root cause is an out-of-bounds write (CWE-787) in PCRE2's JIT stack management. The JIT stack grows downward; before reserving a frame, generated code subtracts the required frame size from the current stack top and compares it against the stack limit. If the new top is below the limit, a shared resize stub lowers the limit by a fixed 8,192 bytes — but this fixed increment is insufficient when a single frame allocation exceeds 8,192 bytes. The resize can succeed and return even though the already-adjusted stack top remains below the new limit, causing subsequent writes to occur outside the permitted stack area. Exploitation requires the application to: (1) enable JIT compilation, (2) create a growable JIT stack via pcre2_jit_stack_create(), (3) assign it using pcre2_jit_stack_assign(), and (4) allow an attacker to supply a regular expression — patterns with very large numbers of capturing groups (e.g., 1,400 distinct referenced captures) can trigger the oversized frame allocation. A standalone C proof-of-concept (pcre2_10_48_jit_stack_underwrite_poc.c) was developed by the reporter and confirmed the issue on Linux/AArch64, macOS/ARM64, and macOS/x86_64 (PCRE2 Advisory).

Impact

Successful exploitation results in an out-of-bounds write with data derived from JIT matching state, which can corrupt adjacent memory regions. Consequences include process crashes (availability impact) and memory corruption that may remain undetected until corrupted data is later used, potentially enabling arbitrary code execution in the context of the application using PCRE2 (integrity and confidentiality impact). The reporter demonstrated command execution through phpMyAdmin's use of an attacker-controlled regular expression as a real-world exploitation scenario, indicating that any application accepting user-supplied regex patterns and using the affected JIT API is at risk (PCRE2 Advisory).

Exploitability

No public proof-of-concept exploit code has been released, and there is no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. However, a private PoC was developed by the original reporter (Michael Allen) and confirmed on multiple platforms, and the advisory notes that further exploitation including arbitrary code execution should be assumed possible (PCRE2 Advisory, Feedly).

Exploitation steps

  1. Identify a vulnerable target: Find an application that accepts user-supplied regular expressions, uses PCRE2 ≤10.48 with JIT enabled, and creates a growable JIT stack via pcre2_jit_stack_create() assigned with pcre2_jit_stack_assign() — web applications like phpMyAdmin are known examples.
  2. Craft a malicious regex pattern: Construct a recursive regular expression with approximately 1,400 or more distinct referenced capturing groups. This forces the JIT compiler to allocate a single stack frame larger than PCRE2's 8,192-byte growth increment (e.g., a 33,640-byte frame on 64-bit systems).
  3. Submit the pattern: Supply the crafted regex to the target application through any input vector that causes it to be JIT-compiled and matched (e.g., a search field, configuration input, or API endpoint accepting regex).
  4. Trigger the stack underwrite: The JIT resize stub lowers the stack limit by only 8,192 bytes, which is insufficient for the oversized frame. The match proceeds, writing below the JIT stack mapping into adjacent memory. The match eventually returns PCRE2_ERROR_JIT_STACKLIMIT (-46), but only after the out-of-bounds writes have occurred.
  5. Achieve memory corruption / code execution: Depending on memory layout, the escaped writes may corrupt an adjacent allocation (e.g., heap metadata, function pointers, or attacker-controlled subject buffer pointers), potentially enabling arbitrary code execution in the application's process context (PCRE2 Advisory).

Indicators of compromise

  • Logs: Application logs showing PCRE2_ERROR_JIT_STACKLIMIT (-46) return codes from regex matching operations, especially when triggered by user-supplied patterns; unexpected application crashes or segmentation faults in processes using PCRE2.
  • Process: Unusual process crashes or core dumps from applications using PCRE2 JIT (e.g., PHP, Apache httpd with mod_rewrite, phpMyAdmin); heap corruption errors reported by memory allocators (e.g., glibc malloc abort messages).
  • Network: Repeated requests to application endpoints that accept regex input, containing patterns with large numbers of capturing groups (e.g., patterns with 1,000+ (...) groups or deep recursion constructs like (?R)).
  • File System: Unexpected core dump files (core.*) in application working directories following regex processing operations (PCRE2 Advisory).

Mitigation and workarounds

Upgrade PCRE2 to version 10.49 or later, which contains the fix in commit 2b4038298072684b0fae29b15bedfb1a75bda46d. Backport patches for supported earlier releases are documented in the project's SUPPORT-LIFECYCLE.md. If immediate upgrading is not feasible, the following workarounds can be applied: (1) do not JIT-compile attacker-controlled regular expressions; (2) avoid assigning a growable JIT stack — allow JIT matching to use the default machine stack instead; or (3) disable JIT matching entirely by passing PCRE2_NO_JIT to pcre2_match(). Note that increasing the maximum JIT stack size is explicitly not a reliable workaround (PCRE2 Advisory, Red Hat Bugzilla).

Community reactions

Red Hat has opened a tracking bug (BZ#2543797) and assigned it high severity, with 17 users on the CC list indicating broad internal attention across RHEL and OpenShift product teams. The PCRE2 maintainer's advisory notes that the vulnerability is not specific to phpMyAdmin and may affect other PHP software and any software using PCRE2, broadening the potential impact scope. Social media activity was observed on Mastodon shortly after disclosure (Red Hat Bugzilla, PCRE2 Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pcre2

Affected

sid

pcre2: 10.48-3.1

Fixed

trixie

pcre2: 10.46-1~deb13u3

Fixed

Ubuntu

Unknown

bionic (esm-apps)

pcre2

Unknown

devel

pcre2

Unknown

focal (esm-infra)

pcre2

Unknown

jammy

pcre2

Unknown

noble

pcre2

Unknown

resolute

pcre2

Unknown

xenial (esm-apps-legacy)

pcre2

Unknown

RHEL / CentOS

Affected

OpenShift

openshift/ose-rhel-coreos-8

Affected

RHEL 8

mariadb:10.11/mariadb.src

Affected

RHEL 9

mariadb:10.11/mariadb.src

Affected

RHEL 10

mariadb10.11.src

Affected

Alpine

Fixed

edge

pcre2: 10.49-r0

Fixed

v3.23

pcre2: 10.49-r0

Fixed

Source: This report was generated using AI

Related MariaDB Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-89161HIGH7.8
  • MariaDB Server logoMariaDB Server
  • mariadb:10.11::mariadb-embedded-devel
NoYesSep 11, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb:11.8::mariadb-common
NoYesSep 30, 2026
CVE-2026-89160MEDIUM6.5
  • MariaDB Server logoMariaDB Server
  • mingw32-pcre2
NoYesSep 11, 2026
CVE-2026-89158MEDIUM6.5
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server-utils
NoYesSep 11, 2026
CVE-2026-89162LOW3.3
  • MariaDB Server logoMariaDB Server
  • mariadb-pam
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management