In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pcre2 | Pcre | 10.45 (including) | 10.48 (excluding) |
| Pcre2 | Pcre | 10.48-rc1 (including) | 10.48-rc1 (including) |
| Red Hat Hardened Images | RedHat | pcre2-main-10.48-0.1.hum1 | * |
| Pcre2 | Ubuntu | upstream | * |