[Git][security-tracker-team/security-tracker][master] Mark temp issues as fixed in pcre2/bookworm

Emilio Pozuelo Monfort (@pochu) pochu at debian.org
Fri Sep 4 11:07:52 BST 2026



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1937a40f by Emilio Pozuelo Monfort at 2026-09-04T12:07:18+02:00
Mark temp issues as fixed in pcre2/bookworm

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3789,26 +3789,31 @@ CVE-2023-31308 (A malicious virtual function can invoke the certain command hand
 CVE-2026-XXXX [GHSA-fmgr-6ggq-9859: PCRE2: integer overflow in pcre2_compile_32() causes out-of-bounds write on 32-bit systems]
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+	[bookworm] - pcre2 10.42-1+deb12u1
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/ec9c286d5c10cf1c388b58a442ccefded42254fd (pcre2-10.48)
 CVE-2026-XXXX [GHSA-9qww-pwc4-77qq: PCRE2: out-of-bounds reads in pcre2_match() when matching invalid UTF subjects with PCRE2_MATCH_INVALID_UTF]
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+	[bookworm] - pcre2 10.42-1+deb12u1
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/4889caf31a4c5a6b3c051f0031bf2dbd78f2c287 (pcre2-10.48)
 CVE-2026-XXXX [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds write in pcre2_pattern_convert() with large patterns on 32-bit systems]
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+	[bookworm] - pcre2 10.42-1+deb12u1
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3 (pcre2-10.48-RC1)
 CVE-2026-XXXX [GHSA-3r4p-g7gg-ppmf: out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit]
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+	[bookworm] - pcre2 10.42-1+deb12u1
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/c932e70451eafef922ebef364ac25042f0031135 (pcre2-10.48)
 CVE-2026-XXXX [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read in pcre2_match() after JIT fallback with invalid UTF]
 	- pcre2 10.48-1
 	[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+	[bookworm] - pcre2 10.42-1+deb12u1
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5 pcre2-10.48-RC1)
 CVE-2026-19873 (HTML::FormFu versions through 2.08 for Perl allow resource exhaustion  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1937a40fb482988dc31ba0219d1b58feddd1b45b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1937a40fb482988dc31ba0219d1b58feddd1b45b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/5c57285b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list