CVE-2025-58050
published 2025-08-27CVE-2025-58050: The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability…
PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.69%
48.9th percentile
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcre2 | < pcre2 10.46-1 (forky) | pcre2 10.46-1 (forky) |
| pcre | pcre2 | — | — |
| pcre | pcre2 | >= 0 < 10.46-1~deb13u1 | 10.46-1~deb13u1 |
| pcre | pcre2 | >= 0 < 10.46-1 | 10.46-1 |
| pcre2project | pcre2 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PCRE2 vulnerability
vendor_ubuntu·2025-09-25
CVE-2025-58050 PCRE2 vulnerability
Title: PCRE2 vulnerability
Summary: PCRE2 could be made to expose sensitive information.
It was discovered that PCRE2 incorrectly handled the Scan SubString verb.
An attacker could possibly use this issue to cause applications using PCRE2
to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS
vendor_redhat·2025-08-27·CVSS 6.9
CVE-2025-58050 [MEDIUM] CWE-125 pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS
pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.
In pcre2 library, there is a vulnerability in the code that causes a heap-buffer-overflow. This arises from using the special verb - Scan-
Debian
CVE-2025-58050: pcre2 - The PCRE2 library is a set of C functions that implement regular expression patt...
vendor_debian·2025·CVSS 6.9
CVE-2025-58050 [MEDIUM] CVE-2025-58050: pcre2 - The PCRE2 library is a set of C functions that implement regular expression patt...
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 10.46-1)
sid: resolved (fixed in 10.46-1)
trixie: resolved (fixed in 10.46-1~deb13u1)
OSV
CVE-2025-58050: The PCRE2 library is a set of C functions that implement regular expression pattern matching
osv·2025-08-27·CVSS 6.9
CVE-2025-58050 [MEDIUM] CVE-2025-58050: The PCRE2 library is a set of C functions that implement regular expression pattern matching
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, April 2026 Security Update Review
blogs_qualys·2026-04-22
CVE-2025-6965 Oracle Critical Patch Update, April 2026 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 481 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 139, constituting about 28% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middleware followed, with 75 and 59 security patches.
376 of the 481 security patches provided by the April Critical Patch Update (about 78%)
Bugzilla
CVE-2025-58050 pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS
bugzilla·2025-08-27·CVSS 6.9
CVE-2025-58050 [MEDIUM] CVE-2025-58050 pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS
CVE-2025-58050 pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.
https://github.com/PCRE2Project/pcre2/commit/a141712e5967d448c7ce13090ab530c8e3d82254https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.46https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-c2gv-xgf5-5cc2https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-c2gv-xgf5-5cc2
2025-08-27
Published