[Git][security-tracker-team/security-tracker][master] perl spu

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 31 22:00:24 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ab9e5f24 by Moritz Mühlenhoff at 2026-08-31T22:59:31+02:00
perl spu

- - - - -


2 changed files:

- data/CVE/list
- data/next-point-update.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -55513,11 +55513,13 @@ CVE-2026-57668 (Improper Neutralization of Input During Web Page Generation ('Cr
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57433 (Storable versions before 3.41 for Perl have a signed integer overflow  ...)
 	- perl 5.40.1-8 (bug #1138906; bug #1142035)
+	[trixie] - perl <no-dsa> (Minor issue)
 	- libstorable-perl <removed>
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780100/
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7 (v5.43.11)
 CVE-2026-57432 (Perl versions through 5.43.10 have an integer overflow in S_measure_st ...)
 	- perl 5.40.1-8 (bug #1138905; bug #1142036)
+	[trixie] - perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780102/
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 (v5.43.11)
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e (v5.43.11)
@@ -55739,6 +55741,7 @@ CVE-2026-14165 (An Authorization Bypass Through User-Controlled Key vulnerabilit
 CVE-2026-13221 (Perl versions through 5.43.9 produce silently incorrect regular expres ...)
 	[experimental] - perl 5.44.0-1
 	- perl 5.42.3-1 (bug #1142037)
+	[trixie] - perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780104/
 	NOTE: https://github.com/Perl/perl5/issues/23388
 	NOTE: Introduced with: https://github.com/Perl/perl5/commit/acababb42be12ff2986b73c1bfa963b70bb5d54e (v5.37.10)
@@ -59211,6 +59214,7 @@ CVE-2026-7017 (HTTP::Tiny versions before 0.095 for Perl forward credential head
 	[bookworm] - libhttp-tiny-perl <postponed> (Minor issue; leak requires caller-supplied credential headers and an attacker-influenced redirect)
 	[experimental] - perl 5.44.0-1
 	- perl 5.42.3-1 (bug #1141639)
+	[trixie] - perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41618211/
 	NOTE: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36
 	NOTE: Fixed by: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3 (release-0.095)
@@ -76392,6 +76396,7 @@ CVE-2026-12087 (Socket versions before 2.041 for Perl have an out-of-bounds heap
 	[bullseye] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
 	[experimental] - perl 5.44.0-1
 	- perl 5.42.3-1 (bug #1140152)
+	[trixie] - perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41020451/
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb (v5.43.11)
 CVE-2026-11832 (Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to  ...)
@@ -91934,6 +91939,7 @@ CVE-2026-48962 (IO::Compress versions before 2.220 for Perl can execute arbitrar
 	- libio-compress-perl 2.220-1 (bug #1138055)
 	[trixie] - libio-compress-perl <no-dsa> (Minor issue)
 	- perl 5.40.1-8 (bug #1138854)
+	[trixie] - perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40434385/
 	NOTE: Fixed by: https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610 (v2.220)
 CVE-2026-48961 (IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetai ...)
@@ -91942,6 +91948,7 @@ CVE-2026-48961 (IO::Compress versions from 2.207 before 2.220 for Perl ship a zi
 	[bookworm] - libio-compress-perl <not-affected> (Vulnerable code introduced later)
 	[bullseye] - libio-compress-perl <not-affected> (Vulnerable code introduced later)
 	- perl 5.40.1-8 (bug #1138855)
+	[trixie] - perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40434383/
 	NOTE: Introduced with: https://github.com/pmqs/IO-Compress/commit/ddfe67584a228877e5d28840da75ff32e435a5e3 (v2.207)
 	NOTE: Fixed by: https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7 (v2.220)
@@ -91949,12 +91956,14 @@ CVE-2026-48959 (IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU e
 	- libio-compress-perl 2.220-1 (bug #1138051)
 	[trixie] - libio-compress-perl <no-dsa> (Minor issue)
 	- perl 5.40.1-8 (bug #1138856)
+	[trixie] - perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40434381/
 	NOTE: Fixed by: https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2 (v2.220)
 CVE-2025-15649 (IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaugh ...)
 	- libio-compress-perl 2.217-1 (bug #1146065)
 	[trixie] - libio-compress-perl <no-dsa> (Minor issue)
 	- perl 5.40.1-8 (bug #1138863)
+	[trixie] - perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40434380/
 	NOTE: https://github.com/pmqs/IO-Compress/issues/65
 	NOTE: Fixed by: https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8 (v2.215)


=====================================
data/next-point-update.txt
=====================================
@@ -498,3 +498,29 @@ CVE-2026-58264
 	[trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
 CVE-2026-61714
 	[trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
+CVE-2026-7017
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-42496
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-42497
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-12087
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-13221
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2025-15649
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-7010
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-8376
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-48959
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-48961
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-48962
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-57432
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-57433
+	[trixie] - perl 5.40.1-6+deb13u1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab9e5f24192426678f81b04e69d4b3fe06cea97b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab9e5f24192426678f81b04e69d4b3fe06cea97b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/902dc881/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list