Summary
OSS-Fuzz has identified a heap-buffer-overflow (WRITE 4) in pcre2_compile_32, reported as OSV-2026-343. The issue has been public since 2026-03-03 but does not appear to have a corresponding GitHub issue or fix.
Details
Questions
- Is this issue already tracked internally via the OSS-Fuzz dashboard?
- Is a fix in progress, or is this considered low priority given that the crash state references
pcre2_fuzzsupport.c?
Context
This was surfaced by an OSV-based vulnerability scan of Homebrew packages. PCRE2 is a transitive dependency of many core tools (git, zsh, ripgrep, etc.), so visibility on the fix timeline would be appreciated.
Summary
OSS-Fuzz has identified a heap-buffer-overflow (WRITE 4) in
pcre2_compile_32, reported as OSV-2026-343. The issue has been public since 2026-03-03 but does not appear to have a corresponding GitHub issue or fix.Details
pcre2_compile_32/pcre2_fuzzsupport.cQuestions
pcre2_fuzzsupport.c?Context
This was surfaced by an OSV-based vulnerability scan of Homebrew packages. PCRE2 is a transitive dependency of many core tools (git, zsh, ripgrep, etc.), so visibility on the fix timeline would be appreciated.