Question about libsocket-perl on trixie

Kentaro HAYASHI kenhys at xdump.org
Mon Aug 17 15:19:47 BST 2026


Hi,

While going through the security tracker I noticed that
libsocket-perl in trixie is still affected by CVE-2026-12087
(out-of-bounds heap read in pack_ip_mreq_source()) [1].

[1] https://security-tracker.debian.org/tracker/CVE-2026-12087

The security team marked it <no-dsa> for trixie, so a fix via
the next point release looks like the appropriate route.
unstable/forky are already fine with 2.041-1.

Do you have plans for this already? If not, I'd be happy to do
the work: I have prepared a minimal backport of the upstream fix
plus a small regression test for 2.038-1.

I see there's no trixie branch in the packaging repository, so I
didn't want to assume anything about the layout.

I've attached drafts and debdiff. I hope it will help.

Best Regards,
-------------- next part --------------
A non-text attachment was scrubbed...
Name: CVE-2026-12087.md
Type: text/markdown
Size: 3840 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-perl-maintainers/attachments/20260817/844ad8ca/attachment.md>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: libsocket-perl_2.038-1+deb13u1.debdiff
Type: application/octet-stream
Size: 11058 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-perl-maintainers/attachments/20260817/844ad8ca/attachment.obj>


More information about the pkg-perl-maintainers mailing list