[Git][security-tracker-team/security-tracker][master] Track CVE fixes for perl issues addressed via experimental
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 3 19:36:48 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
73b6441c by Salvatore Bonaccorso at 2026-08-03T20:36:15+02:00
Track CVE fixes for perl issues addressed via experimental
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -20918,6 +20918,7 @@ CVE-2026-14453 (This vulnerability is a critical Server-Side Template Injection
CVE-2026-14165 (An Authorization Bypass Through User-Controlled Key vulnerability affe ...)
NOT-FOR-US: Dassault Systemes
CVE-2026-13221 (Perl versions through 5.43.9 produce silently incorrect regular expres ...)
+ [experimental] - perl 5.44.0-1
- perl <unfixed> (bug #1142037)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780104/
NOTE: https://github.com/Perl/perl5/issues/23388
@@ -24307,6 +24308,7 @@ CVE-2026-7017 (HTTP::Tiny versions before 0.095 for Perl forward credential head
- libhttp-tiny-perl 0.096-1 (bug #1141638)
[trixie] - libhttp-tiny-perl <no-dsa> (Minor issue)
[bookworm] - libhttp-tiny-perl <postponed> (Minor issue; leak requires caller-supplied credential headers and an attacker-influenced redirect)
+ [experimental] - perl 5.44.0-1
- perl <unfixed> (bug #1141639)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41618211/
NOTE: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36
@@ -41412,6 +41414,7 @@ CVE-2026-12087 (Socket versions before 2.041 for Perl have an out-of-bounds heap
[trixie] - libsocket-perl <no-dsa> (Minor issue)
[bookworm] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
[bullseye] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
+ [experimental] - perl 5.44.0-1
- perl <unfixed> (bug #1140152)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41020451/
NOTE: Fixed by: https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb (v5.43.11)
@@ -57575,18 +57578,21 @@ CVE-2026-48715 (radvd is a router advertisement daemon for IPv6. Prior to versio
NOTE: https://github.com/radvd-project/radvd/security/advisories/GHSA-52px-gh9p-m379
NOTE: Crash in CLI tool, no security impact
CVE-2026-9538 (Archive::Tar versions before 3.10 for Perl allow memory exhaustion via ...)
+ [experimental] - perl 5.44.0-1
- perl <unfixed> (bug #1138861)
[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396448/
NOTE: https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7 (3.10)
CVE-2026-42497 (Archive::Tar versions before 3.08 for Perl extract hardlinks to attack ...)
+ [experimental] - perl 5.44.0-1
- perl <unfixed> (bug #1138859)
[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396457/
NOTE: https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158 (3.08)
CVE-2026-42496 (Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...)
+ [experimental] - perl 5.44.0-1
- perl <unfixed> (bug #1138860)
[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73b6441c0ba1dd70f8d5a8aea9eddf13a75c66ae
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73b6441c0ba1dd70f8d5a8aea9eddf13a75c66ae
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/d7b05f90/attachment.htm>
More information about the debian-security-tracker-commits
mailing list