[security][CVE-2026-86145] PCRE2 in Bun and Redis runtime images #172

Open
opened 2026-09-16 13:22:48 +00:00 by dirtydishes · 0 comments
Owner

Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status fixed, which means a patch is available, not installed.

CVE: CVE-2026-86145
Severity: High. CVSS: redhat: 8.2

Affected versions

Project impact

The Dockerfiles use oven/bun:1.3.11 and Compose uses redis:7.2. Both resolved linux/amd64 images contain the affected PCRE2 library. This is inherited OS-library exposure. Application-triggered exploitation is not established: it requires the PCRE2 API usage described below, not ordinary JavaScript regular expressions. Patch the inherited library to remove the vulnerable code.

Advisory description

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

Remediation

Use rebuilt image tags/digests containing the distro fixes listed below, or PCRE2 10.48 or later. Rebuild app images, then rescan the exact resulting digests. Do not assume that a floating tag has picked up the fix.

Run counters, globally deduplicated by CVE ID

unaddressed critical CVEs: 6
unaddressed medium/low CVEs: 184
unaddressed total CVEs: 271

These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository.

Resolution checks

Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one.

Sources

Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status `fixed`, which means a patch is available, not installed. CVE: CVE-2026-86145 Severity: High. CVSS: redhat: 8.2 Affected versions - bun: libpcre2-8-0@10.46-1~deb13u1; distro fix 10.46-1~deb13u2 - redis: libpcre2-8-0@10.42-1; distro fix 10.42-1+deb12u1 Project impact The Dockerfiles use oven/bun:1.3.11 and Compose uses redis:7.2. Both resolved linux/amd64 images contain the affected PCRE2 library. This is inherited OS-library exposure. Application-triggered exploitation is not established: it requires the PCRE2 API usage described below, not ordinary JavaScript regular expressions. Patch the inherited library to remove the vulnerable code. Advisory description PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API). Remediation Use rebuilt image tags/digests containing the distro fixes listed below, or PCRE2 10.48 or later. Rebuild app images, then rescan the exact resulting digests. Do not assume that a floating tag has picked up the fix. Run counters, globally deduplicated by CVE ID unaddressed critical CVEs: 6 unaddressed medium/low CVEs: 184 unaddressed total CVEs: 271 These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository. Resolution checks Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one. Sources - https://www.cve.org/CVERecord?id=CVE-2026-86145 - https://nvd.nist.gov/vuln/detail/CVE-2026-86145 - https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#172
No description provided.