CVE Vulnerabilities

CVE-2026-89162

Incorrect Resource Transfer Between Spheres

Published: Sep 11, 2026 | Modified: Sep 16, 2026
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
2.9 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

Weakness

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Affected Software

NameVendorStart VersionEnd Version
Pcre2Pcre10.45 (including)10.48 (excluding)
Pcre2Pcre10.48-rc1 (including)10.48-rc1 (including)
Red Hat Hardened ImagesRedHatpcre2-main-10.48-0.1.hum1*
Pcre2Ubuntuupstream*

References