Out-of-bounds read in PCRE2 - CVE-2025-58050

 

Out-of-bounds read in PCRE2 - CVE-2025-58050

Published: September 26, 2025


Vulnerability identifier: #VU116129
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58050
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in the PCRE2 regular expression matching engine during handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

PCRE2
Oracle Communications Operations Monitor
otp
Communications Unified Assurance
Ubuntu
Fedora
pcre2 (Ubuntu package)
pcre2

How to mitigate CVE-2025-58050

Install updates from vendor's website.

PCRE2 - update to 10.46
otp - update to 28.0.3
pcre2 (Ubuntu package) - update to 10.45-1ubuntu0.1
pcre2 - update to 10.46-1.fc42

External References

Related Security Bulletins