Bug#1144498: perl: 8 unpatched security CVEs - request fix for trixie
Mohammad, Ejas Ali
ejas.ali.mohammad at accenture.com
Sun Aug 16 08:33:45 BST 2026
Package: perl
Version: 5.40.1-6
Severity: Critical & High
Hi Debian Security Team,
The following CVEs are reported against the perl source package in Trixie and have no fix available at time of filing.
S.No
CVE
CVSS
Component
Issue
1
CVE-2026-57433
9.8
Storable
Signed integer overflow on SX_HOOK deserialization; crafted thaw() input panics the process
2
CVE-2026-12087
9.1
Socket
pack_ip_mreq_source() validates wrong argument length; heap out-of-bounds read up to 3 bytes
3
CVE-2026-13221
9.1
perl core (regex)
Alternation > 65535 branches overflows 16-bit trie field; silent false-positive/negative matches
4
CVE-2026-57432
8.4
perl core (pack/un
Integer overflow in S_measure_struct; large repeat count leaks heap memory to caller
5
CVE-2026-48959
7.5
IO::Uncompress
fastForward() compares offset digit count instead of offset value; CPU exhaustion on crafted zip
6
CVE-2026-48962
7.3
IO::Compress
File::GlobMapper runs caller-supplied output glob through eval STRING; arbitrary code execution
7
CVE-2026-48961
7.3
IO::Compress
zipdetails crashes on Info-ZIP Unix Extra Field with 8-byte UID/GID; undefined subroutine
8
CVE-2026-7017
7.1
HTTP::Tiny
Authorization/Cookie headers forwarded to cross-origin redirect targets without origin check
All eight CVEs show Fix Status: open on the Debian security tracker. Please provide patched packages for trixie.
Regards,
Ejas Ali
________________________________
This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security, AI-powered support capabilities, and assessment of internal compliance with Accenture policy. Your privacy is important to us. Accenture uses your personal data only in compliance with data protection laws. For further information on how Accenture processes your personal data, please see our privacy statement at https://www.accenture.com/us-en/privacy-policy.
______________________________________________________________________________________
www.accenture.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/perl-maintainers/attachments/20260816/9d7a2dfb/attachment-0001.htm>
More information about the Perl-maintainers
mailing list