diff mbox series

[AUH] libpcre2: upgrading to 10.49 SUCCEEDED

Message ID 010101a0ebd0ca19-e8538a16-6229-4061-8bbb-a6dd3a79d435-000000@us-west-2.amazonses.com
State New
Headers show
Series [AUH] libpcre2: upgrading to 10.49 SUCCEEDED | expand

Commit Message

auh@yoctoproject.org Sept. 29, 2026, 6:18 a.m. UTC
Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *libpcre2* to *10.49* has Succeeded.

Next steps:
    - apply the patch: git am 0001-libpcre2-upgrade-10.48-10.49.patch
    - check the changes to upstream patches and summarize them in the commit message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update failures.
Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From 5aaa53e9188f5e46ed743d97a73d020055724357 Mon Sep 17 00:00:00 2001
From: Upgrade Helper <auh@yoctoproject.org>
Date: Tue, 29 Sep 2026 06:18:33 +0000
Subject: [PATCH] libpcre2: upgrade 10.48 -> 10.49

Version 10.49 28-September-2026
-------------------------------

This is a security-only release, to address GHSA-r9hj-j2rw-4q3m.

Compared to 10.48, this release has only a minimal code change to prevent an
out-of-bounds write with arbitrary data. An attacker-controlled regex pattern
is required, and applications are only affected if using the
pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable
JIT stack, and then matching against a pattern with unusually high JIT stack
usage, such as a large number of capturing groups.

The implications of an out-of-bounds write could include arbitrary code
execution.

The issue is not a regression and affects releases 10.48 and earlier.
---
 .../libpcre/{libpcre2_10.48.bb => libpcre2_10.49.bb}            | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-support/libpcre/{libpcre2_10.48.bb => libpcre2_10.49.bb} (96%)
diff mbox series

Patch

diff --git a/meta/recipes-support/libpcre/libpcre2_10.48.bb b/meta/recipes-support/libpcre/libpcre2_10.49.bb
similarity index 96%
rename from meta/recipes-support/libpcre/libpcre2_10.48.bb
rename to meta/recipes-support/libpcre/libpcre2_10.49.bb
index d5daff03c0..8e0c44fb4c 100644
--- a/meta/recipes-support/libpcre/libpcre2_10.48.bb
+++ b/meta/recipes-support/libpcre/libpcre2_10.49.bb
@@ -19,7 +19,7 @@  SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \
 GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases"
 UPSTREAM_CHECK_REGEX = "releases/tag/pcre2-(?P<pver>\d+(\.\d+)+)$"
 
-SRC_URI[sha256sum] = "b6c68fdf6f3ac31388b50aa89ff0fc49c00c987c16e7b5146491d12003f2c8ed"
+SRC_URI[sha256sum] = "53c156e1ba416a20da8e65395daa132da0d80e76910424caca3fcdae7831d384"
 
 CVE_PRODUCT = "pcre2"