Release date:
2026-09-16 09:52:57 UTC
Description:
* SECURITY UPDATE: path traversal in Archive::Tar via unvalidated
symlink and hardlink targets in the tar header
- debian/patches/CVE-2026-42496.patch: reject absolute and
escaping '..' link targets in Archive::Tar::_make_special_file()
unless $Archive::Tar::INSECURE_EXTRACT_MODE is set, resolving the
target through _symlinks_resolver() so links that stay inside the
extraction directory keep working
- CVE-2026-42496
* SECURITY UPDATE: memory exhaustion in Archive::Tar via an
attacker-controlled entry size field in the tar header
- debian/patches/CVE-2026-9538.patch: cap the per-entry declared size
in Archive::Tar::_read_tar() with $Archive::Tar::MAX_FILE_SIZE
(default 1 GiB), refusing the entry before the read buffer is
allocated
- CVE-2026-9538
* SECURITY UPDATE: arbitrary code execution in File::GlobMapper via an
attacker-controlled output glob
- debian/patches/CVE-2026-48962.patch: replace the eval STRING in
File::GlobMapper::_getFiles() with literal substitution of the
internal markers set up by _parseOutputGlob() in
cpan/IO-Compress/lib/File/GlobMapper.pm
- CVE-2026-48962
* SECURITY UPDATE: integer overflow when computing a pack/unpack
template structure size
- debian/patches/CVE-2026-57432.patch: croak in S_measure_struct() in
pp_pack.c when the computed structure size would overflow SSize_t,
and document the new diagnostic in pod/perldiag.pod
- CVE-2026-57432
* SECURITY UPDATE: signed integer overflow when deserializing a crafted
Storable SX_HOOK record
- debian/patches/CVE-2026-57433.patch: reject a hook data item count
of I32_MAX in retrieve_hook_common() in dist/Storable/Storable.xs
before it is incremented and passed to av_extend()
- CVE-2026-57433
* SECURITY UPDATE: HTTP::Tiny did not verify TLS certificates by default
- debian/patches/CVE-2023-31486.patch: default verify_SSL to 1 in
cpan/HTTP-Tiny/lib/HTTP/Tiny.pm and add the
PERL_HTTP_TINY_SSL_INSECURE_BY_DEFAULT escape hatch, matching
HTTP::Tiny 0.083
- CVE-2023-31486
Updated packages:
-
libperl-dev_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
sha:1a6956afb227bedc374aa9250dd54ac476b6264b
-
libperl5.32_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
sha:0ecc5ff0c3598f3b0f874a3aa259ff4f91b7a2f3
-
perl_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
sha:d257dfc5c365323e855091dca771e75f528a6502
-
perl-base_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
sha:09183484d8f499759c147b7c53d9b5c09db08549
-
perl-debug_5.32.1-4+deb11u5+tuxcare.els4_amd64.deb
sha:6e0e3a727492b7661f61bf9db60b88bc2bbf6506
-
perl-doc_5.32.1-4+deb11u5+tuxcare.els4_all.deb
sha:eb69eaede7bd086a82600297c4fbb569e72fe95a
-
perl-modules-5.32_5.32.1-4+deb11u5+tuxcare.els4_all.deb
sha:3d33d8119478b00f31d4ca105cb9689a61bb305d
-
libperl-dev_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
sha:f4446402007ddaa6b6257d12992d1825d5cbdc78
-
libperl5.32_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
sha:6db8bb9b23a56793f9ad75d0d737321b9759df92
-
perl_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
sha:324230b84416841567f66bb26a102c0d68ebe56a
-
perl-base_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
sha:d07e459c52d252d7bc95b7ce78d0fedf01edeb7b
-
perl-debug_5.32.1-4+deb11u5+tuxcare.els4_arm64.deb
sha:23a61e7ba75a0e87ef15e5f7e9387351133ec6fd
-
libperl-dev_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
sha:9d9ba18c338067cd0a41668ddd0ca9ee3116fe2d
-
libperl5.32_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
sha:a250244445433c78f46478c1f3ae3af24461f4d6
-
perl_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
sha:1a5360a3ef627521cfaabdbb75d9035baa927c27
-
perl-base_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
sha:ef8e14ec2d669e08816610c94fdc931523c80528
-
perl-debug_5.32.1-4+deb11u5+tuxcare.els4_armel.deb
sha:c8d4fe04d03b8e43401c8abbaabeb08e09465c2f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.