[Git][security-tracker-team/security-tracker][master] Track CVE fixes for perl issues addressed via experimental

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 3 19:36:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
73b6441c by Salvatore Bonaccorso at 2026-08-03T20:36:15+02:00
Track CVE fixes for perl issues addressed via experimental

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -20918,6 +20918,7 @@ CVE-2026-14453 (This vulnerability is a critical Server-Side Template Injection
 CVE-2026-14165 (An Authorization Bypass Through User-Controlled Key vulnerability affe ...)
 	NOT-FOR-US: Dassault Systemes
 CVE-2026-13221 (Perl versions through 5.43.9 produce silently incorrect regular expres ...)
+	[experimental] - perl 5.44.0-1
 	- perl <unfixed> (bug #1142037)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780104/
 	NOTE: https://github.com/Perl/perl5/issues/23388
@@ -24307,6 +24308,7 @@ CVE-2026-7017 (HTTP::Tiny versions before 0.095 for Perl forward credential head
 	- libhttp-tiny-perl 0.096-1 (bug #1141638)
 	[trixie] - libhttp-tiny-perl <no-dsa> (Minor issue)
 	[bookworm] - libhttp-tiny-perl <postponed> (Minor issue; leak requires caller-supplied credential headers and an attacker-influenced redirect)
+	[experimental] - perl 5.44.0-1
 	- perl <unfixed> (bug #1141639)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41618211/
 	NOTE: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36
@@ -41412,6 +41414,7 @@ CVE-2026-12087 (Socket versions before 2.041 for Perl have an out-of-bounds heap
 	[trixie] - libsocket-perl <no-dsa> (Minor issue)
 	[bookworm] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
 	[bullseye] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
+	[experimental] - perl 5.44.0-1
 	- perl <unfixed> (bug #1140152)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41020451/
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb (v5.43.11)
@@ -57575,18 +57578,21 @@ CVE-2026-48715 (radvd is a router advertisement daemon for IPv6. Prior to versio
 	NOTE: https://github.com/radvd-project/radvd/security/advisories/GHSA-52px-gh9p-m379
 	NOTE: Crash in CLI tool, no security impact
 CVE-2026-9538 (Archive::Tar versions before 3.10 for Perl allow memory exhaustion via ...)
+	[experimental] - perl 5.44.0-1
 	- perl <unfixed> (bug #1138861)
 	[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
 	[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396448/
 	NOTE: https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7 (3.10)
 CVE-2026-42497 (Archive::Tar versions before 3.08 for Perl extract hardlinks to attack ...)
+	[experimental] - perl 5.44.0-1
 	- perl <unfixed> (bug #1138859)
 	[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
 	[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396457/
 	NOTE: https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158 (3.08)
 CVE-2026-42496 (Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...)
+	[experimental] - perl 5.44.0-1
 	- perl <unfixed> (bug #1138860)
 	[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
 	[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73b6441c0ba1dd70f8d5a8aea9eddf13a75c66ae

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73b6441c0ba1dd70f8d5a8aea9eddf13a75c66ae
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/d7b05f90/attachment.htm>


More information about the debian-security-tracker-commits mailing list