[LFS Trac] #5976: perl CVE-2026-13221 and 57432
LFS Trac ([email protected] via lfs-book Mailing List) <[email protected]> Mon, 13 Jul 2026 23:01:55 -0000
| Newsgroups | gmane.linux.lfs.book |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format...
------------=_1783983720-1024790-3958
Content-Type: multipart/related;
boundary="===============3187360370844401990=="
--===============3187360370844401990==
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
#5976: perl CVE-2026-13221 and 57432
-------------------------+----------------------
Reporter: Joe Locash | Owner: lfs-book
Type: enhancement | Status: new
Priority: normal | Milestone: 13.1
Component: Book | Version: git
Severity: normal | Keywords:
-------------------------+----------------------
Just reporting for those interested.
{{{
Message-Id: <[email protected]>
Date: Mon, 13 Jul 2026 17:43:01 +0200
From: Stig Palmquist <[email protected]>
To: [email protected],
[email protected]
Subject: CVE-2026-13221: Perl versions through 5.43.9 produce silently
incorrect regular expression matches when an alternation of more than
65535
fixed string branches is compiled into a trie in Perl_study_chunk
========================================================================
CVE-2026-13221 CPAN Security Group
========================================================================
CVE ID: CVE-2026-13221
Distribution: perl
Versions: through 5.43.9
MetaCPAN: https://metacpan.org/dist/perl
VCS Repo: https://github.com/Perl/perl5
Perl versions through 5.43.9 produce silently incorrect regular
expression matches when an alternation of more than 65535 fixed string
branches is compiled into a trie in Perl_study_chunk
Description
-----------
Perl versions through 5.43.9 produce silently incorrect regular
expression matches when an alternation of more than 65535 fixed string
branches is compiled into a trie in Perl_study_chunk.
When such branches are combined into a trie, the delta between the
first branch and the shared tail is stored in a 16-bit field. A branch
count above 65535 overflows the field, and the trie's match decision
table is truncated with no warning or error.
A pattern of this shape produces false positive matches (matching
strings it should not) and false negative matches (failing to match
strings it should). When such a pattern gates an access or filtering
decision, the result is wrong.
Problem types
-------------
- CWE-190 Integer Overflow or Wraparound
Solutions
---------
Apply the upstream patch. The fix is included in the Perl 5.43.10
development release.
References
----------
https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch
https://github.com/Perl/perl5/issues/23388
}}}
{{{
Message-Id: <[email protected]>
Date: Mon, 13 Jul 2026 17:45:47 +0200
From: Stig Palmquist <[email protected]>
To: [email protected],
[email protected]
Subject: CVE-2026-57432: Perl versions through 5.43.10 have an integer
overflow in S_measure_struct leading to an out-of-bounds heap read in
pack
and unpack
========================================================================
CVE-2026-57432 CPAN Security Group
========================================================================
CVE ID: CVE-2026-57432
Distribution: perl
Versions: through 5.43.10
MetaCPAN: https://metacpan.org/dist/perl
VCS Repo: https://github.com/Perl/perl5
Perl versions through 5.43.10 have an integer overflow in
S_measure_struct leading to an out-of-bounds heap read in pack and
unpack
Description
-----------
Perl versions through 5.43.10 have an integer overflow in
S_measure_struct leading to an out-of-bounds heap read in pack and
unpack.
S_measure_struct adds each item's size times its repeat count to a
running total with no overflow check, so a large repeat count in a pack
or unpack template wraps the signed SSize_t total negative. The @, X,
and x position codes then guard their moves with a signed length
comparison that passes when the length is negative, advancing the
buffer pointer out of bounds.
A template derived from untrusted input can read heap memory past the
buffer and return it to the caller.
Problem types
-------------
- CWE-190 Integer Overflow or Wraparound
- CWE-125 Out-of-bounds Read
Solutions
---------
Apply the upstream patches. The fix is included in the Perl 5.43.11
development release.
References
----------
https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch
https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5976>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.
--===============3187360370844401990==--
------------=_1783983720-1024790-3958
Content-Type: text/plain; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
--
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
------------=_1783983720-1024790-3958--