new file mode 100644
@@ -0,0 +1,111 @@
+From 2b4038298072684b0fae29b15bedfb1a75bda46d Mon Sep 17 00:00:00 2001
+From: Zoltan Herczeg <zherczeg@inf.u-szeged.hu>
+Date: Mon, 21 Sep 2026 07:46:13 +0000
+Subject: [PATCH] Fix large JIT stack allocation
+
+(GHSA-r9hj-j2rw-4q3m) Security fix to prevent an out of bounds write with
+arbitrary data. Applications are only affected if using the
+pcre2_jit_stack_assign() API to create a growable JIT stack, and then matching
+against a pattern with an extremely JIT stack usage, such as a large number of
+capturing groups.
+
+The implications of an out of bounds write could include arbitrary code
+execution.
+
+The issue is not a regression and affects releases 10.48 and earlier.
+
+CVE: CVE-2026-103111
+Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/2b4038298072684b0fae29b15bedfb1a75bda46d]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/pcre2_jit_compile.c | 21 +++++++++++++++++++--
+ testdata/testinput17 | 5 +++++
+ testdata/testoutput17 | 6 ++++++
+ 3 files changed, 30 insertions(+), 2 deletions(-)
+
+diff --git a/src/pcre2_jit_compile.c b/src/pcre2_jit_compile.c
+index 105a1dd3..c5da883c 100644
+--- a/src/pcre2_jit_compile.c
++++ b/src/pcre2_jit_compile.c
+@@ -99,7 +99,7 @@ Fast, but limited size. */
+
+ /* Growth rate for stack allocated by the OS. Should be the multiply
+ of page size. */
+-#define STACK_GROWTH_RATE 8192
++#define STACK_GROWTH_RATE (sljit_sw)8192
+
+ /* Enable to check that the allocation could destroy temporaries. */
+ #if defined SLJIT_DEBUG && SLJIT_DEBUG
+@@ -472,6 +472,8 @@ typedef struct compiler_common {
+ BOOL local_quit_available;
+ /* Currently in a positive assertion. */
+ BOOL in_positive_assertion;
++ /* More than STACK_GROWTH_RATE / 2 stack memory is allocated. */
++ BOOL large_stack_allocation;
+ /* Newline control. */
+ int nltype;
+ sljit_u32 nlmax;
+@@ -3523,6 +3525,8 @@ static SLJIT_INLINE void allocate_stack(compiler_common *common, sljit_s32 size)
+ DEFINE_COMPILER;
+
+ SLJIT_ASSERT(size > 0);
++if (size > (STACK_GROWTH_RATE / (SSIZE_OF(sw) * 2)))
++ common->large_stack_allocation = TRUE;
+ OP2(SLJIT_SUB, STACK_TOP, 0, STACK_TOP, 0, SLJIT_IMM, size * SSIZE_OF(sw));
+ #ifdef DESTROY_REGISTERS
+ OP1(SLJIT_MOV, TMP1, 0, SLJIT_IMM, 12345);
+@@ -13974,7 +13978,20 @@ SLJIT_ASSERT(TMP1 == SLJIT_R0 && STR_PTR == SLJIT_R1);
+
+ OP1(SLJIT_MOV, SLJIT_MEM1(SLJIT_SP), LOCAL1, STR_PTR, 0);
+ OP1(SLJIT_MOV, SLJIT_R0, 0, ARGUMENTS, 0);
+-OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_LIMIT, 0, SLJIT_IMM, STACK_GROWTH_RATE);
++if (common->large_stack_allocation)
++ {
++ SLJIT_COMPILE_ASSERT((STACK_GROWTH_RATE & (STACK_GROWTH_RATE - 1)) == 0, stack_growth_must_be_power_of_2);
++ // Negative difference. The positive difference would also use the same amount
++ // of operations, but the last subtraction emits several instructions on x86.
++ OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_TOP, 0, STACK_LIMIT, 0);
++ // Minimum extra space after allocation.
++ OP2(SLJIT_SUB, SLJIT_R1, 0, SLJIT_R1, 0, SLJIT_IMM, (STACK_GROWTH_RATE / 2));
++ // Rounds down negative numbers.
++ OP2(SLJIT_AND, SLJIT_R1, 0, SLJIT_R1, 0, SLJIT_IMM, ~(STACK_GROWTH_RATE - 1));
++ OP2(SLJIT_ADD, SLJIT_R1, 0, SLJIT_R1, 0, STACK_LIMIT, 0);
++ }
++else
++ OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_LIMIT, 0, SLJIT_IMM, STACK_GROWTH_RATE);
+ OP1(SLJIT_MOV, SLJIT_R0, 0, SLJIT_MEM1(SLJIT_R0), SLJIT_OFFSETOF(jit_arguments, stack));
+ OP1(SLJIT_MOV, STACK_LIMIT, 0, TMP2, 0);
+
+diff --git a/testdata/testinput17 b/testdata/testinput17
+index a02e6be2..486998b4 100644
+--- a/testdata/testinput17
++++ b/testdata/testinput17
+@@ -188,6 +188,11 @@
+ /(?(R)a*(?1)|((?R))b)/
+ \= Expect JIT stack limit reached
+ aaaabcde
++
++# A single large stack allocation must grow beyond the current stack top.
++
++/((?(DEFINE)\[()\g{-1}]{1400}).{1}(?R)|)/expand,jit
++ AAAAAA\=jitstack=192
+
+ # Invalid options disable JIT when called via pcre2_match(), causing the
+ # match to happen via the interpreter, but for fast JIT invalid options are
+diff --git a/testdata/testoutput17 b/testdata/testoutput17
+index c678587f..b6e7e1a6 100644
+--- a/testdata/testoutput17
++++ b/testdata/testoutput17
+@@ -350,6 +350,12 @@ Failed: error -46: JIT stack limit reached
+ \= Expect JIT stack limit reached
+ aaaabcde
+ Failed: error -46: JIT stack limit reached
++
++# A single large stack allocation must grow beyond the current stack top.
++
++/((?(DEFINE)\[()\g{-1}]{1400}).{1}(?R)|)/expand,jit
++ AAAAAA\=jitstack=192
++Failed: error -46: JIT stack limit reached
+
+ # Invalid options disable JIT when called via pcre2_match(), causing the
+ # match to happen via the interpreter, but for fast JIT invalid options are
@@ -21,6 +21,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \
file://CVE-2026-89160.patch \
file://CVE-2026-89158.patch \
file://CVE-2026-86145.patch \
+ file://CVE-2026-103111.patch \
"
GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases"