Out-of-bounds read in PCRE2 - CVE-2025-58050
Published: September 26, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in the PCRE2 regular expression matching engine during handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
Oracle Communications Operations Monitor
otp
Communications Unified Assurance
Ubuntu
Fedora
pcre2 (Ubuntu package)
pcre2
How to mitigate CVE-2025-58050
otp - update to 28.0.3
pcre2 (Ubuntu package) - update to 10.45-1ubuntu0.1
pcre2 - update to 10.46-1.fc42