Ubuntu alert USN-8406-1 (libnet-cidr-lite-perl)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8406-1] Net::CIDR::Lite vulnerabilities | |
| Date: | Mon, 08 Jun 2026 18:18:54 +0000 | |
| Message-ID: | <E1wWeYo-0000p5-8D@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8406-1 June 08, 2026 libnet-cidr-lite-perl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Net::CIDR::Lite. Software Description: - libnet-cidr-lite-perl: module for merging IPv4 or IPv6 CIDR address ranges Details: Dave Rolsky discovered that Net::CIDR::Lite did not properly handle extraneous zero characters at the beginning of an IP address string. A remote attacker could possibly use this issue to bypass access controls that are based on IP addresses. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2021-47154) It was discovered that Net::CIDR::Lite did not properly validate the IPv6 group count when handling uncompressed IPv6 addresses. A remote attacker could possibly use this issue to bypass access controls. (CVE-2026-40198) It was discovered that Net::CIDR::Lite mishandled IPv4 mapped IPv6 addresses. A remote attacker could possibly use this issue to bypass access controls that are based on IP addresses. (CVE-2026-40199) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnet-cidr-lite-perl 0.22-2ubuntu0.26.04.1 Ubuntu 25.10 libnet-cidr-lite-perl 0.22-2ubuntu0.25.10.1 Ubuntu 24.04 LTS libnet-cidr-lite-perl 0.22-2ubuntu0.24.04.1 Ubuntu 22.04 LTS libnet-cidr-lite-perl 0.22-1ubuntu0.1 Ubuntu 20.04 LTS libnet-cidr-lite-perl 0.21-2ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libnet-cidr-lite-perl 0.21-1ubuntu0.18.04.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libnet-cidr-lite-perl 0.21-1ubuntu0.16.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8406-1 CVE-2021-47154, CVE-2026-40198, CVE-2026-40199 Package Information: https://launchpad.net/ubuntu/+source/libnet-cidr-lite-per... https://launchpad.net/ubuntu/+source/libnet-cidr-lite-per... https://launchpad.net/ubuntu/+source/libnet-cidr-lite-per... https://launchpad.net/ubuntu/+source/libnet-cidr-lite-per...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmonBw8ACgkQcpJm3tlz hgFiqA//TursyEGZXR9kK3RoxmRLlPnz8lDwBxhdErdZNNoN+K9fgxucmLXOWDCX Dh/ctwuB4Rz25M7V2WWqa5i6aS4WGw+rx7EHIVpIPSYVNH2Pl2FcJ6/lwsXdoHvv unhu2Ew47NK5VE4sM4BpxeQJryKmPSXRWXCq8DyXASeegLm5o7rwcu154vgDL0KO s73h9FF9b8nvvj/zUf6YYgB2j/pakpTYJQa0adR7kCUBlbZE28eL5CjZ+inOLNMl 8qkU8Zu0npoz8U1ZJU2zxS9S4hoC4HA93qJbPe1VC2+mJlWo5dE/JayEnLubqSx0 MZXKQlYM5G7KykJLfS7UKuVGB5Pd7QAemP4a3+bdsI9mOZkebCp7EUUlzzxQ/duN GHx2ZcMbcQaB+Cguo91N3ehW/e2ki7DGq5J5rdReZk6vRSOKdMftT7W38DIdy00v 3ZqqVawIkM9gJjczJlIFw4F/nOoHmBFvo7IaJ84kZ1XcJfzUcVFtlu8ebzW/royC PLIK2Gqf2e9X69R/AI2yaMBb/+ehY+2bPS/E7aDKbw2l6BNUp1cOh2kNwxJD3J/x idf5lgHUleOgOjdovT0/VyYI7mePndP4neAXnUFuYv1rQ2tA0SAIadvqKGytowCS t0rTR3jbNVByU2kPJcFXX+aOkEHOxKoEVtV3Vd7011Cc+n5coiM= =8Gh9 -----END PGP SIGNATURE-----
