Bug#1146110: qtbase-opensource-src: please update bundled pcre2 (allocation overflow, commit 8156b39)

Gajendra Nath Soren <[email protected]>
Newsgroups gmane.linux.debian.devel.qt-kde
Message-ID <CABivTSkuVA5Er7gdBUKRtq47w1+vGr7OKZzdkFsmZekZfbd+Vw__41321.0229527735$1788041608$gmane$org@mail.gmail.com>
Package: qtbase-opensource-src
Version: 5.15.19+dfsg-4
Severity: minor
Tags: security
X-Debbugs-Cc: [email protected]

qtbase-opensource-src vendors a copy of pcre2 at:
src/3rdparty/pcre2/src/pcre2_substring.c

This copy predates commit 8156b39 (August 9, 2026) which fixes an
integer overflow in pcre2_substring.c and pcre2_convert.c. The fix
adds an overflow guard:

if (size > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1)) - 1)
return PCRE2_ERROR_NOMEMORY;

Note: the canonical Debian pcre2 package (10.46-1) also does not yet
contain this fix.

No CVE has been assigned yet. The fix is public at:
https://github.com/PCRE2Project/pcre2/commit/8156b39

Please update the bundled pcre2 to the latest upstream version.

Found by: Attack of the Clones GSoC 2026 pipeline
(salsa.debian.org/rouca/gsoc2026)

Gajendra Nath Soren
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.