CVE-2026-89161
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-590
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- PCRE PCRE2
Weakness type
Related vulnerabilities
- CVE-2026-18582 — mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap
- CVE-2025-7006 — Avast antivirus use of stack memory after free when scanning a malformed PE file
- CVE-2026-47328 — Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling
- CVE-2026-20810 — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2025-54899 — Microsoft Excel Remote Code Execution Vulnerability
- CVE-2025-42996 — Multiple vulnerabilities in SAP MDM Server
- CVE-2025-42995 — Multiple vulnerabilities in SAP MDM Server
- CVE-2025-42994 — Multiple vulnerabilities in SAP MDM Server