Notification of new security release

6 views
Skip to first unread message

Nicholas Wilson

unread,
Aug 8, 2026, 9:22:24 AM (5 days ago) Aug 8
to PCRE2 discussion list
During the next week, I expect to make a release of PCRE2, 10.48.

During the last month, we have had various issues reported through use of AI tooling, which I regard as helpful. However, this does change things a little: it is likely that bad actors have done their own scanning, and may already know about the issues.

My previous process of using GitHub's private issue tracker (GHSA) for security issues is probably not providing much protection. So, the issues have not formally been disclosed, but I realise that they may still be considered "public" in the new AI landscape.

I apologise that I haven't responded as promptly to these reports as I should.

Also, 10.48 has been planned (for quite a while) as being the first release with maintainer-provided backports of serious issues. For the fixes I make in the 10.48 release, I do intend to provide patches for the last few releases as well, which will hopefully assist with maintenance of stable Linux distributions.

Unless there is strong demand, I am not planning to embargo the 10.48 release (ie develop its source in private until the day of release).

Let me know how you feel about these plans.

All the best,
Nick

Matthew Vernon

unread,
Aug 8, 2026, 10:05:01 AM (5 days ago) Aug 8
to pcre...@googlegroups.com
Hi,

On 08/08/2026 14:22, Nicholas Wilson wrote:

> Also, 10.48 has been planned (for quite a while) as being the first
> release with maintainer-provided backports of serious issues. For the
> fixes I make in the 10.48 release, I do intend to provide patches for
> the last few releases as well, which will hopefully assist with
> maintenance of stable Linux distributions.

Couple of questions, if I may:

0) do you plan to issue a 10.47 with the fix to #846 applied (and/or an
official patch-to-10.47 to address it)?
1) any chance of a 1.48-RC I can feed to debusine for build-testing
against all the immediate dependencies in Debian, please?

[I think at this point I'm likely to just want to move to 10.48 in
unstable/testing straight away, but a chance to pick up any unexpected
regressions that could be easy fixes would be nice]

Thanks,

Matthew

Nicholas Wilson

unread,
Aug 8, 2026, 11:17:39 AM (5 days ago) Aug 8
to PCRE2 discussion list
Hi Matthew!

Good questions.

0) I will produce official patches for 10.47 and earlier.
1) I don't have an RC, but I can send one to you happily before releasing, which is testing I would gladly appreciate

Nick

Matthew Vernon

unread,
Aug 11, 2026, 5:58:18 AM (2 days ago) Aug 11
to pcre...@googlegroups.com
Hi,
On 08/08/2026 16:17, Nicholas Wilson wrote:

> 1) I don't have an RC, but I can send one to you happily before
> releasing, which is testing I would gladly appreciate

Cool. If you can provide a source tarball for the RC (like a real
release), I can do that. For reference (and as a baseline to compare it
against), I've done some testing on 10.47-2. This gets us two sets of
outputs:

a) run autopkgtests of the reverse-dependencies (i.e. everything that
depends on pcre2 directly) that are in unstable and were thus built
against 10.46-1:
https://debusine.debian.net/debian/developers/work-request/998078/

That has a couple of failures we saw before[0] and know are false-positives:
389-ds-base
ganglia

A couple of failures were we'd filed bugs and fixes were meant to have
been deployed, which is a bit worrying:
remctl
glib2.0

And some new failures, none of which I think are pcre2 bugs, but worth
knowing about:
cyrus-imapd [failing elsewhere]
libselinux [installability, not a pcre2 issue]
sssd [installability, not a pcre2 issue]
swi-prolog [fails on ppc64el only]
syslog-ng [installability, not a pcre2 issue]

b) attempted a rebuild of every reverse-dependency against 10.47-2

This resulted in 10 build failures:

android-platform-external-libselinux [existing FTBFS bug]
crystal [dependency problem]
ganglia [flagged above]
mydumper [cmakefile too old]
ohcount [existing FTBFS bug]
pftools [architecture incompatibility, not a pcre issue]
prelude-lml [existing FTBFS bug]
rspamd [existing FTBFS bug]
shadowsocks-libev [existing FTBFS bug]
virt-v2v [I don't think a pcre problem, fails in repro-build testing]

So it's worth checking what's up with glib2.0 and remctl (both of which
work OK if built with 10.47-2, but fail their autopkgtests when built
with 10.46 and run with 10.47). But this gives us a useful baseline to
compare a 10.48 RC with.

I hope that's at least somewhat helpful, and sorry for the wall of text!

Regards,

Matthew

[0] https://github.com/PCRE2Project/pcre2/issues/832#issuecomment-3476465586

Reply all
Reply to author
Forward
0 new messages