[LFS Trac] #5976: perl CVE-2026-13221 and 57432

LFS Trac ([email protected] via lfs-book Mailing List) <[email protected]> Mon, 13 Jul 2026 23:01:55 -0000
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
This is a multi-part message in MIME format...

------------=_1783983720-1024790-3958
Content-Type: multipart/related;
 boundary="===============3187360370844401990=="

--===============3187360370844401990==
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit

#5976: perl CVE-2026-13221 and 57432
-------------------------+----------------------
 Reporter:  Joe Locash   |      Owner:  lfs-book
     Type:  enhancement  |     Status:  new
 Priority:  normal       |  Milestone:  13.1
Component:  Book         |    Version:  git
 Severity:  normal       |   Keywords:
-------------------------+----------------------
 Just reporting for those interested.

 {{{
 Message-Id: <[email protected]>
 Date: Mon, 13 Jul 2026 17:43:01 +0200
 From: Stig Palmquist <[email protected]>
 To: [email protected],
  [email protected]
 Subject: CVE-2026-13221: Perl versions through 5.43.9 produce silently
  incorrect regular expression matches when an alternation of more than
 65535
  fixed string branches is compiled into a trie in Perl_study_chunk

 ========================================================================
 CVE-2026-13221                                       CPAN Security Group
 ========================================================================

         CVE ID:  CVE-2026-13221
   Distribution:  perl
       Versions:  through 5.43.9

       MetaCPAN:  https://metacpan.org/dist/perl
       VCS Repo:  https://github.com/Perl/perl5


 Perl versions through 5.43.9 produce silently incorrect regular
 expression matches when an alternation of more than 65535 fixed string
 branches is compiled into a trie in Perl_study_chunk

 Description
 -----------
 Perl versions through 5.43.9 produce silently incorrect regular
 expression matches when an alternation of more than 65535 fixed string
 branches is compiled into a trie in Perl_study_chunk.

 When such branches are combined into a trie, the delta between the
 first branch and the shared tail is stored in a 16-bit field. A branch
 count above 65535 overflows the field, and the trie's match decision
 table is truncated with no warning or error.

 A pattern of this shape produces false positive matches (matching
 strings it should not) and false negative matches (failing to match
 strings it should). When such a pattern gates an access or filtering
 decision, the result is wrong.

 Problem types
 -------------
 - CWE-190 Integer Overflow or Wraparound

 Solutions
 ---------
 Apply the upstream patch. The fix is included in the Perl 5.43.10
 development release.


 References
 ----------
 https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch
 https://github.com/Perl/perl5/issues/23388
 }}}

 {{{
 Message-Id: <[email protected]>
 Date: Mon, 13 Jul 2026 17:45:47 +0200
 From: Stig Palmquist <[email protected]>
 To: [email protected],
  [email protected]
 Subject: CVE-2026-57432: Perl versions through 5.43.10 have an integer
  overflow in S_measure_struct leading to an out-of-bounds heap read in
 pack
  and unpack

 ========================================================================
 CVE-2026-57432                                       CPAN Security Group
 ========================================================================

         CVE ID:  CVE-2026-57432
   Distribution:  perl
       Versions:  through 5.43.10

       MetaCPAN:  https://metacpan.org/dist/perl
       VCS Repo:  https://github.com/Perl/perl5


 Perl versions through 5.43.10 have an integer overflow in
 S_measure_struct leading to an out-of-bounds heap read in pack and
 unpack

 Description
 -----------
 Perl versions through 5.43.10 have an integer overflow in
 S_measure_struct leading to an out-of-bounds heap read in pack and
 unpack.

 S_measure_struct adds each item's size times its repeat count to a
 running total with no overflow check, so a large repeat count in a pack
 or unpack template wraps the signed SSize_t total negative. The @, X,
 and x position codes then guard their moves with a signed length
 comparison that passes when the length is negative, advancing the
 buffer pointer out of bounds.

 A template derived from untrusted input can read heap memory past the
 buffer and return it to the caller.

 Problem types
 -------------
 - CWE-190 Integer Overflow or Wraparound
 - CWE-125 Out-of-bounds Read

 Solutions
 ---------
 Apply the upstream patches. The fix is included in the Perl 5.43.11
 development release.


 References
 ----------
 https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch
 https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5976>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

--===============3187360370844401990==--

------------=_1783983720-1024790-3958
Content-Type: text/plain; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page

------------=_1783983720-1024790-3958--