[Git][security-tracker-team/security-tracker][master] Track fixes via unstable for perl issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 18 07:29:57 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2e6a5060 by Salvatore Bonaccorso at 2026-08-18T08:29:34+02:00
Track fixes via unstable for perl issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -39190,7 +39190,7 @@ CVE-2026-14165 (An Authorization Bypass Through User-Controlled Key vulnerabilit
NOT-FOR-US: Dassault Systemes
CVE-2026-13221 (Perl versions through 5.43.9 produce silently incorrect regular expres ...)
[experimental] - perl 5.44.0-1
- - perl <unfixed> (bug #1142037)
+ - perl 5.42.3-1 (bug #1142037)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780104/
NOTE: https://github.com/Perl/perl5/issues/23388
NOTE: Introduced with: https://github.com/Perl/perl5/commit/acababb42be12ff2986b73c1bfa963b70bb5d54e (v5.37.10)
@@ -42615,7 +42615,7 @@ CVE-2026-7017 (HTTP::Tiny versions before 0.095 for Perl forward credential head
[trixie] - libhttp-tiny-perl <no-dsa> (Minor issue)
[bookworm] - libhttp-tiny-perl <postponed> (Minor issue; leak requires caller-supplied credential headers and an attacker-influenced redirect)
[experimental] - perl 5.44.0-1
- - perl <unfixed> (bug #1141639)
+ - perl 5.42.3-1 (bug #1141639)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41618211/
NOTE: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36
NOTE: Fixed by: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3 (release-0.095)
@@ -59786,7 +59786,7 @@ CVE-2026-12087 (Socket versions before 2.041 for Perl have an out-of-bounds heap
[bookworm] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
[bullseye] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
[experimental] - perl 5.44.0-1
- - perl <unfixed> (bug #1140152)
+ - perl 5.42.3-1 (bug #1140152)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41020451/
NOTE: Fixed by: https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb (v5.43.11)
CVE-2026-11832 (Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to ...)
@@ -75984,21 +75984,21 @@ CVE-2026-48715 (radvd is a router advertisement daemon for IPv6. Prior to versio
NOTE: Crash in CLI tool, no security impact
CVE-2026-9538 (Archive::Tar versions before 3.10 for Perl allow memory exhaustion via ...)
[experimental] - perl 5.44.0-1
- - perl <unfixed> (bug #1138861)
+ - perl 5.42.3-1 (bug #1138861)
[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396448/
NOTE: https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7 (3.10)
CVE-2026-42497 (Archive::Tar versions before 3.08 for Perl extract hardlinks to attack ...)
[experimental] - perl 5.44.0-1
- - perl <unfixed> (bug #1138859)
+ - perl 5.42.3-1 (bug #1138859)
[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396457/
NOTE: https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158 (3.08)
CVE-2026-42496 (Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...)
[experimental] - perl 5.44.0-1
- - perl <unfixed> (bug #1138860)
+ - perl 5.42.3-1 (bug #1138860)
[trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396459/
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e6a50604ccaad1d69ee631b8154a3fe5f892f98
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e6a50604ccaad1d69ee631b8154a3fe5f892f98
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/4246514c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list