RHSA-2026:67534HighCVSS 8.2

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
September 15, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-86145 — pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions CVE-2026-89156 — PCRE2: PCRE2: Out-of-bounds read via invalid UTF data during JIT fallback CVE-2026-89157 — pcre2: PCRE2: Out-of-bounds write via large pattern input CVE-2026-89158 — PCRE2: PCRE2: Out-of-bounds write via integer overflow on 32-bit platforms CVE-2026-89160 — pcre2: PCRE2: Denial of Service via out-of-bounds read during invalid UTF matching CVE-2026-89161 — pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match CVE-2026-89162 — pcre2: PCRE2: Information disclosure via pcre2_serialize_encode

🎯 Affected products16

  • Red Hat Hardened Images
  • pcre2-0:10.48-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • pcre2-0:10.48-0.1.hum1@src as a component of Red Hat Hardened Images
  • pcre2-0:10.48-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • pcre2-devel-0:10.48-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • pcre2-devel-0:10.48-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • pcre2-static-0:10.48-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • pcre2-static-0:10.48-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • pcre2-syntax-0:10.48-0.1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
  • pcre2-syntax-0:10.48-0.1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
  • pcre2-tools-0:10.48-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • pcre2-tools-0:10.48-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • pcre2-utf16-0:10.48-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • pcre2-utf16-0:10.48-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • pcre2-utf32-0:10.48-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • pcre2-utf32-0:10.48-0.1.hum1@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this Improper Protection of Alternate Path vulnerability, ensure that secondary execution branches—such as the reuse of cached memory workspaces—enforce the exact same size and boundary checks as the primary memory allocation paths. Limit exposure by preventing untrusted user input from directly controlling PCRE2 regular expressions, and strictly avoid utilizing recursive matching patterns when operating under a low heap limit. Apply a defense-in-depth strategy by validating all inputs comprehensively. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (11)