[CLSA-2026:1789552364] Fix of 7 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-16 09:52:57 UTC
Description:
* SECURITY UPDATE: path traversal in Archive::Tar via unvalidated symlink and hardlink targets in the tar header - debian/patches/CVE-2026-42496.patch: reject absolute and escaping '..' link targets in Archive::Tar::_make_special_file() unless $Archive::Tar::INSECURE_EXTRACT_MODE is set, resolving the target through _symlinks_resolver() so links that stay inside the extraction directory keep working - CVE-2026-42496 * SECURITY UPDATE: memory exhaustion in Archive::Tar via an attacker-controlled entry size field in the tar header - debian/patches/CVE-2026-9538.patch: cap the per-entry declared size in Archive::Tar::_read_tar() with $Archive::Tar::MAX_FILE_SIZE (default 1 GiB), refusing the entry before the read buffer is allocated - CVE-2026-9538 * SECURITY UPDATE: arbitrary code execution in File::GlobMapper via an attacker-controlled output glob - debian/patches/CVE-2026-48962.patch: replace the eval STRING in File::GlobMapper::_getFiles() with literal substitution of the internal markers set up by _parseOutputGlob() in cpan/IO-Compress/lib/File/GlobMapper.pm - CVE-2026-48962 * SECURITY UPDATE: integer overflow when computing a pack/unpack template structure size - debian/patches/CVE-2026-57432.patch: croak in S_measure_struct() in pp_pack.c when the computed structure size would overflow SSize_t, and document the new diagnostic in pod/perldiag.pod - CVE-2026-57432 * SECURITY UPDATE: signed integer overflow when deserializing a crafted Storable SX_HOOK record - debian/patches/CVE-2026-57433.patch: reject a hook data item count of I32_MAX in retrieve_hook_common() in dist/Storable/Storable.xs before it is incremented and passed to av_extend() - CVE-2026-57433 * SECURITY UPDATE: HTTP::Tiny did not verify TLS certificates by default - debian/patches/CVE-2023-31486.patch: default verify_SSL to 1 in cpan/HTTP-Tiny/lib/HTTP/Tiny.pm and add the PERL_HTTP_TINY_SSL_INSECURE_BY_DEFAULT escape hatch, matching HTTP::Tiny 0.083 - CVE-2023-31486
Updated packages:
  • libperl-dev_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
    sha:1a6956afb227bedc374aa9250dd54ac476b6264b
  • libperl5.32_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
    sha:0ecc5ff0c3598f3b0f874a3aa259ff4f91b7a2f3
  • perl_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
    sha:d257dfc5c365323e855091dca771e75f528a6502
  • perl-base_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
    sha:09183484d8f499759c147b7c53d9b5c09db08549
  • perl-debug_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
    sha:6e0e3a727492b7661f61bf9db60b88bc2bbf6506
  • perl-doc_5.32.1-4+deb11u5+tuxcare.els4_all.deb
    sha:eb69eaede7bd086a82600297c4fbb569e72fe95a
  • perl-modules-5.32_5.32.1-4+deb11u5+tuxcare.els4_all.deb
    sha:3d33d8119478b00f31d4ca105cb9689a61bb305d
  • libperl-dev_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
    sha:f4446402007ddaa6b6257d12992d1825d5cbdc78
  • libperl5.32_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
    sha:6db8bb9b23a56793f9ad75d0d737321b9759df92
  • perl_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
    sha:324230b84416841567f66bb26a102c0d68ebe56a
  • perl-base_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
    sha:d07e459c52d252d7bc95b7ce78d0fedf01edeb7b
  • perl-debug_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
    sha:23a61e7ba75a0e87ef15e5f7e9387351133ec6fd
  • libperl-dev_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
    sha:9d9ba18c338067cd0a41668ddd0ca9ee3116fe2d
  • libperl5.32_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
    sha:a250244445433c78f46478c1f3ae3af24461f4d6
  • perl_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
    sha:1a5360a3ef627521cfaabdbb75d9035baa927c27
  • perl-base_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
    sha:ef8e14ec2d669e08816610c94fdc931523c80528
  • perl-debug_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
    sha:c8d4fe04d03b8e43401c8abbaabeb08e09465c2f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.