new file mode 100644
@@ -0,0 +1,61 @@
+From 8156b3989a82f2ddf9504d8248496e9b124be7f3 Mon Sep 17 00:00:00 2001
+From: Ilia Alshanetsky <ilia@ilia.ws>
+Date: Sun, 9 Aug 2026 07:15:03 -0400
+Subject: [PATCH] Use CU2BYTES for byte sizing in two allocation sites (#909)
+
+Two allocation sites multiplied by PCRE2_CODE_UNIT_WIDTH (the bit width:
+8, 16, or 32) where the CU2BYTES(x) byte-count helper is intended. The
+result over-allocates by the code-unit byte width: 8x in 8-bit mode, 16x
+in 16-bit, 32x in 32-bit. Subsequent memcpy calls already use CU2BYTES
+correctly, so no out-of-bounds write occurs; the over-allocation is
+leaked until the buffer is freed.
+
+Also guard each site against integer overflow in
+sizeof(pcre2_memctl) + CU2BYTES(N + 1) by rejecting N greater than
+(PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1) - 1.
+
+CVE: CVE-2026-89157
+Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/pcre2_convert.c | 8 +++++---
+ src/pcre2_substring.c | 7 ++++---
+ 2 files changed, 9 insertions(+), 6 deletions(-)
+
+diff --git a/src/pcre2_convert.c b/src/pcre2_convert.c
+index ad7312ab..8a2b293d 100644
+--- a/src/pcre2_convert.c
++++ b/src/pcre2_convert.c
+@@ -1215,9 +1215,11 @@ for (int i = 0; i < 2; i++)
+ /* Allocate memory for the buffer, with hidden space for an allocator at
+ the start. The next time round the loop runs the conversion for real. */
+
+- allocated = PRIV(memctl_malloc)(sizeof(pcre2_memctl) +
+- (*bufflenptr + 1)*PCRE2_CODE_UNIT_WIDTH, (pcre2_memctl *)ccontext);
+- if (allocated == NULL)
++ if (*bufflenptr > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) /
++ CU2BYTES(1)) - 1 ||
++ (allocated = PRIV(memctl_malloc)(sizeof(pcre2_memctl) +
++ CU2BYTES(*bufflenptr + 1),
++ (pcre2_memctl *)ccontext)) == NULL)
+ {
+ *bufflenptr = 0; /* Error offset */
+ return PCRE2_ERROR_NOMEMORY;
+diff --git a/src/pcre2_substring.c b/src/pcre2_substring.c
+index f68b464e..a6f5277a 100644
+--- a/src/pcre2_substring.c
++++ b/src/pcre2_substring.c
+@@ -210,9 +210,10 @@ PCRE2_SIZE size;
+ PCRE2_UCHAR *yield;
+ rc = pcre2_substring_length_bynumber(match_data, stringnumber, &size);
+ if (rc < 0) return rc;
+-yield = PRIV(memctl_malloc)(sizeof(pcre2_memctl) +
+- (size + 1)*PCRE2_CODE_UNIT_WIDTH, (pcre2_memctl *)match_data);
+-if (yield == NULL) return PCRE2_ERROR_NOMEMORY;
++if (size > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1)) - 1 ||
++ (yield = PRIV(memctl_malloc)(sizeof(pcre2_memctl) +
++ CU2BYTES(size + 1), (pcre2_memctl *)match_data)) == NULL)
++ return PCRE2_ERROR_NOMEMORY;
+ yield = (PCRE2_UCHAR *)(((char *)yield) + sizeof(pcre2_memctl));
+ if (size != 0) memcpy(yield, match_data->subject + match_data->ovector[stringnumber*2],
+ CU2BYTES(size));
@@ -17,6 +17,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \
file://CVE-2026-89162.patch \
file://CVE-2026-89161.patch \
file://CVE-2026-89156.patch \
+ file://CVE-2026-89157.patch \
"
GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases"