Critical severity9.1NVD Advisory· Published Aug 27, 2025· Updated Jun 17, 2026
CVE-2025-58050
CVE-2025-58050
Description
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords5 versionspkg:rpm/opensuse/pcre2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/pcre2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/pcre2&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/pcre2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/pcre2&distro=SUSE%20Linux%20Micro%206.2
< 10.45-160000.3.1+ 4 more
- (no CPE)range: < 10.45-160000.3.1
- (no CPE)range: < 10.46-1.1
- (no CPE)range: < 10.45-160000.3.1
- (no CPE)range: < 10.45-160000.3.1
- (no CPE)range: < 10.45-160000.3.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.