This is a security-only release, to address GHSA-r9hj-j2rw-4q3m.
Compared to 10.48, this release has only a minimal code change to prevent an out-of-bounds write with arbitrary data. An attacker-controlled regular expression is required. Applications are affected only when they use pcre2_jit_stack_create() and pcre2_jit_stack_assign() to provide a growable JIT stack, then match a pattern with unusually high JIT stack usage, such as one containing a large number of capturing groups.
The implications of an out-of-bounds write could include arbitrary code execution.
The issue is not a regression and affects releases 10.48 and earlier. Users should upgrade to 10.49. Backport patches for supported earlier releases are listed in SUPPORT-LIFECYCLE.md.
This release is available as a signed Git tag, or alternatively as a signed tarball of the Git tag (attestation).