|
|
Log in / Subscribe / Register

Ubuntu alert USN-8467-2 (perl)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8467-2] Perl vulnerabilities
Date:  Fri, 03 Jul 2026 12:33:03 +0000
Message-ID:  <E1wfd4p-00005B-T3@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8467-2 July 02, 2026 perl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: Several security issues were fixed in Perl. Software Description: - perl: Practical Extraction and Report Language Details: USN-8467-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 25.10. Original advisory details: It was discovered that Perl's Archive::Tar module incorrectly handled symlink and hardlink targets during extraction. An attacker could use this issue to read or overwrite arbitrary files outside the extraction directory. (CVE-2026-42496) It was discovered that Perl had a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-8376) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libperl-dev 5.40.1-6ubuntu0.1 libperl5.40 5.40.1-6ubuntu0.1 perl 5.40.1-6ubuntu0.1 perl-base 5.40.1-6ubuntu0.1 perl-debug 5.40.1-6ubuntu0.1 perl-modules-5.40 5.40.1-6ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8467-2 https://ubuntu.com/security/notices/USN-8467-1 CVE-2026-42496, CVE-2026-8376 Package Information: https://launchpad.net/ubuntu/+source/perl/5.40.1-6ubuntu0.1


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpGKdcACgkQcpJm3tlz hgHN9xAAptLeMEPlXc93B9GYzWW2lRDHTXMLkWvKOG9/6O30HBNhEN1BarbYOvik fmeeSgtL+3irekJcfjkj6sGh+6jazBNW9gGvzo/wT5p9fZyoYL3QRnoyMWPB78/D iwPBVVbYU/nJXYdWjVQTK+d6wMEPZTktVTje+XkaSAKT0Tx259QeDi0dAvHnxg+e vTyqMYc1s4BGryA32uxJgSCp2XIEzvqDViYvtzV8BMNmrBarqkv6R1qO2mK1LOCf 5qnXcT46Spk6UmpJ95eqoJcg5TzI4SSaoogjETmB4CJLwmSEk4sVoLPPPL6FEtOa kpv5O2TBkpWwA7YDP4lY5L5W5Nln9NPAxcE9YYUw2oytKXhzi0LBIeIFvXr8bNh5 uWpXHXQI6F7LQdP/q8YqGAkRqz4TFyu4lrrYNoaQUvd44W0xAohkSz+xQL4j+2Rl CX36113nBTeQxVbjcMaejkJ1srQUXckOK1DJswTQ/YEiNqLmcekjFK8esuK+D0ZC 3c4DUibTg+aKEB4NJ6RCNUASl1RvZWkjvCs71Wk9Pgw7zhT1n2GIhlcAxj46NVcg zNSn4t8orpU7+qutafdvr7/d2/uDLkc0p0uCU6w/gKM3eUMSPXZtVcAY4sJEKZT6 SNielSvyMx/1mRVePBMeuad1QOOPHM1PKGMV+stEAzXjn4Ov4+Y= =pMxl -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds