Ubuntu alert USN-8467-1 (perl)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8467-1] Perl vulnerabilities | |
| Date: | Wed, 24 Jun 2026 14:17:00 +0000 | |
| Message-ID: | <E1wcOPU-0000Mo-C9@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8467-1 June 24, 2026 perl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Perl. Software Description: - perl: Practical Extraction and Report Language Details: It was discovered that Perl's Archive::Tar module incorrectly handled symlink and hardlink targets during extraction. An attacker could use this issue to read or overwrite arbitrary files outside the extraction directory. (CVE-2026-42496) It was discovered that Perl had a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-8376) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libperl-dev 5.30.0-9ubuntu0.5+esm2 Available with Ubuntu Pro libperl5.30 5.30.0-9ubuntu0.5+esm2 Available with Ubuntu Pro perl 5.30.0-9ubuntu0.5+esm2 Available with Ubuntu Pro perl-base 5.30.0-9ubuntu0.5+esm2 Available with Ubuntu Pro perl-debug 5.30.0-9ubuntu0.5+esm2 Available with Ubuntu Pro perl-doc 5.30.0-9ubuntu0.5+esm2 Available with Ubuntu Pro perl-modules-5.30 5.30.0-9ubuntu0.5+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libperl-dev 5.26.1-6ubuntu0.7+esm2 Available with Ubuntu Pro libperl5.26 5.26.1-6ubuntu0.7+esm2 Available with Ubuntu Pro perl 5.26.1-6ubuntu0.7+esm2 Available with Ubuntu Pro perl-base 5.26.1-6ubuntu0.7+esm2 Available with Ubuntu Pro perl-debug 5.26.1-6ubuntu0.7+esm2 Available with Ubuntu Pro perl-doc 5.26.1-6ubuntu0.7+esm2 Available with Ubuntu Pro perl-modules-5.26 5.26.1-6ubuntu0.7+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS libperl-dev 5.22.1-9ubuntu0.9+esm2 Available with Ubuntu Pro libperl5.22 5.22.1-9ubuntu0.9+esm2 Available with Ubuntu Pro perl 5.22.1-9ubuntu0.9+esm2 Available with Ubuntu Pro perl-base 5.22.1-9ubuntu0.9+esm2 Available with Ubuntu Pro perl-debug 5.22.1-9ubuntu0.9+esm2 Available with Ubuntu Pro perl-doc 5.22.1-9ubuntu0.9+esm2 Available with Ubuntu Pro perl-modules-5.22 5.22.1-9ubuntu0.9+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS libperl-dev 5.18.2-2ubuntu1.7+esm7 Available with Ubuntu Pro perl 5.18.2-2ubuntu1.7+esm7 Available with Ubuntu Pro perl-base 5.18.2-2ubuntu1.7+esm7 Available with Ubuntu Pro perl-debug 5.18.2-2ubuntu1.7+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8467-1 CVE-2026-8376
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo749EACgkQcpJm3tlz hgHWww/8C/m0gFiTJPjzzOZIT7Di68vFnMDr8yp7ctQm1tX4AqhtEoJDAhjbRMh9 PGBhpMaNapFRcPOVuvcTE1xAPIPEQWLFHXwquFM/27EmxNCBk4+Qqcte8scv2nbv wr4kpsMcFDXPpKBZLqdjYMVHFSylJOIF/33WZFAEy70Mj8URF1muS7Y+vyIm4wgy ntEUjs3iP4LJ4zCLNjyai8vse+eEa9Eg1J/YgsIP9pbTcRUKYABHKr/+o8TdaT0E /xbCiubTwXPReT2ecl9Nq4Ili7l8mlLMU3PQb864THWQO9YKDEl8goNnf/6lvRzC M+n53PEUo296WVWTA9zKs9WXmKxzqDdSbGoS9R6ik6KF2LN/FUcNp/q8rJx70Po+ ECbisf0VJ4uk9GEJPPGeo6jYDW3oZNzdq5XMGKQpbiV5RNxZ+nRQReW5kbTJWO4s L3X5jQE1BEhwJOimFuqKR69lXij4NeTyS8H6vzm3jepb0RCBiLs4GByaIEPU8R94 0ZE4K07sASXirqX63Np/GWmM+ufLrvaXG1pq02yn/IRr8ooFwOjWjYWQhk+kqtVK 1kpmplMpxY46VEs17bibwohbXkEiL8F5TPh+S0SiBFp7O1tnl7IQ52KWsgUuZjsI KydjD3mDvYpLzA8+NvZ3CIfU+q9p99Z/jRINvv0B5YJHB5Vpe7Q= =OTEU -----END PGP SIGNATURE-----
