[From nobody Sat Jun  6 18:35:14 2026
Received: (at 1138856-close) by bugs.debian.org; 6 Jun 2026 17:34:01 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-113.0 required=4.0 tests=BAYES_00,DKIM_SIGNED,
 DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,FVGT_m_MULTI_ODD,
 HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,RCVD_IN_DNSWL_MED,
 SPF_HELO_PASS,SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 6; hammy, 150; neutral, 204; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--HX-DAK:process-upload,
 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo.
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from mitropoulos.debian.org
 ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:45940)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wVuuH-0046q7-0E for 1138856-close@bugs.debian.org;
 Sat, 06 Jun 2026 17:34:01 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by mitropoulos.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wVuuF-008ZO1-1U for 1138856-close@bugs.debian.org;
 Sat, 06 Jun 2026 17:33:59 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=FfOmMD1M2JSemZfm417ltlqayVSCpflvSVJbxju8Azg=; b=oFiArg0zBvNKqJSHv2JM9uL8C8
 TAl0sSXRF2UpswA+GO+2rlPlhzY6UWSeuaXZ51GB0W1Xy8VRWzeQZOPk2s92ImxQw93s5QEwNIntz
 9EZ1TbVtItWvACCp75h1+BBxXIgY+1sGp8Md4eQIjcAfr7s392SFIwnNW86TGsm74gsjeel6q9EdL
 0iO4rV9/lQFRp+Mo8oeYvMB9eYA2ZJ4AZKdQkqSoL6ke6wxh1/6HnJTNyzFH6gh6P+DjhHar+N68D
 AGfEmtuDJozeYf+o9IBwDla39u5SpgRECAkLSjlxMWTG2nY+0Fu7RR/7g4q4P7RezZk1tByfHQWXX
 Q9HEcYLQ==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wVuuE-00000008c40-1FLi; Sat, 06 Jun 2026 17:33:58 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Niko Tyni &lt;ntyni@debian.org&gt;
To: 1138856-close@bugs.debian.org
X-DAK: dak process-upload
X-Debian: DAK
X-Debian-Package: perl
Debian: DAK
Debian-Changes: perl_5.42.2-2_source.changes
Debian-Source: perl
Debian-Version: 5.42.2-2
Debian-Architecture: source
Debian-Suite: experimental
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1138856: fixed in perl 5.42.2-2
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============5773915299858273212==&quot;
Message-Id: &lt;E1wVuuE-00000008c40-1FLi@fasolo.debian.org&gt;
Date: Sat, 06 Jun 2026 17:33:58 +0000

--===============5773915299858273212==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: perl
Source-Version: 5.42.2-2
Done: Niko Tyni &lt;ntyni@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138856@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Niko Tyni &lt;ntyni@debian.org&gt; (supplier of updated perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA384

Format: 1.8
Date: Sat, 06 Jun 2026 18:02:30 +0300
Source: perl
Architecture: source
Version: 5.42.2-2
Distribution: experimental
Urgency: medium
Maintainer: Niko Tyni &lt;ntyni@debian.org&gt;
Changed-By: Niko Tyni &lt;ntyni@debian.org&gt;
Closes: 1137345 1138854 1138855 1138856 1138858 1138863 1138905 1138906
Changes:
 perl (5.42.2-2) experimental; urgency=3Dmedium
 .
   * [SECURITY] backport various fixes from upstream:
     + CVE-2025-15649: header parsing in IO::Uncompress::Unzip.
         (Closes: #1138863)
     + CVE-2026-7010:  CRLF-validation in HTTP::Tiny.
         (Closes: #1138858)
     + CVE-2026-8376:  Buffer overflow in Perl_study_chunk.
         (Closes: #1137345)
     + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.
         (Closes: #1138856)
     + CVE-2026-48961: crash in zipdetails.
         (Closes: #1138855)
     + CVE-2026-48962: code execution in IO-Compress via output globs.
         (Closes: #1138854)
     + buffer overflows in pack().
         (Closes: #1138905)
     + buffer overflow in Storable.
         (Closes: #1138906)
Checksums-Sha1:
 fac7a2aa4e40bb502f1d0ce479f05bb76f4e7fe1 2372 perl_5.42.2-2.dsc
 9060d73f124395f973a8cfe3d6e412fbb93217ce 175608 perl_5.42.2-2.debian.tar.xz
 9cea33e3faf2aceb567e9db40aa4fff67e9264ad 5338 perl_5.42.2-2_source.buildinfo
Checksums-Sha256:
 e33c40124c7932ccebc7343c768e74347545dabf04b48a7b94a3b8d1a829a15c 2372 perl_5=
.42.2-2.dsc
 03dc1d547aa8271832042b2a66b8c71a72035c28ca736166fd27dc6d2aaa8afb 175608 perl=
_5.42.2-2.debian.tar.xz
 1b9c3872189b57ee52820e2d497dd8e99fdfb243e03a872f0013322a801380b2 5338 perl_5=
.42.2-2_source.buildinfo
Files:
 13b7988bfedecc286305774e1817e7d0 2372 perl standard perl_5.42.2-2.dsc
 0a7ad2361cdc8b893dbcad3628bcd09f 175608 perl standard perl_5.42.2-2.debian.t=
ar.xz
 8ed1e5c781a84858dfb01c5d963d86a3 5338 perl standard perl_5.42.2-2_source.bui=
ldinfo

-----BEGIN PGP SIGNATURE-----

iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCaiRCvBEcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5soOOAXoDqPuy2hIDNgbVMnotKgfi7tU1TjmeDkEC
OfUCv1UOU/zgnn4mqFkVY0EtjSc74iUBf3LHLX7Tab7loNX6UtKcvkCmoY1uXvWf
a7YWnv6aOXsw9oPetRDgHQcOE9AHI6Mz8w=3D=3D
=3DYN5x
-----END PGP SIGNATURE-----


--===============5773915299858273212==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaiRaBgAKCRCb9qggYcy5
ITSJAQDDmIF3MA2tDNPbHjsnnnxdRtB/lIANLsmpHm3Y0CO1UQEA39SJCmy3Vd/9
n0tPZ3bSwr6UNMvEOGBEbe6Mj/8wBAI=
=b0P3
-----END PGP SIGNATURE-----

--===============5773915299858273212==--
]