Bug#1146110: qtbase-opensource-src: please update bundled pcre2 (allocation overflow, commit 8156b39)
Gajendra Nath Soren <[email protected]>
| Newsgroups | gmane.linux.debian.devel.qt-kde |
|---|---|
| Message-ID | <CABivTSkuVA5Er7gdBUKRtq47w1+vGr7OKZzdkFsmZekZfbd+Vw__41321.0229527735$1788041608$gmane$org@mail.gmail.com> |
Package: qtbase-opensource-src Version: 5.15.19+dfsg-4 Severity: minor Tags: security X-Debbugs-Cc: [email protected] qtbase-opensource-src vendors a copy of pcre2 at: src/3rdparty/pcre2/src/pcre2_substring.c This copy predates commit 8156b39 (August 9, 2026) which fixes an integer overflow in pcre2_substring.c and pcre2_convert.c. The fix adds an overflow guard: if (size > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1)) - 1) return PCRE2_ERROR_NOMEMORY; Note: the canonical Debian pcre2 package (10.46-1) also does not yet contain this fix. No CVE has been assigned yet. The fix is public at: https://github.com/PCRE2Project/pcre2/commit/8156b39 Please update the bundled pcre2 to the latest upstream version. Found by: Attack of the Clones GSoC 2026 pipeline (salsa.debian.org/rouca/gsoc2026) Gajendra Nath Soren [email protected]