#1138649 libunicode-linebreak-perl: CVE-2026-8594

#1138649#5
Date:
2026-06-01 18:44:27 UTC
From:
To:
Hi,

The following vulnerability was published for libunicode-linebreak-perl.

CVE-2026-8594[0]:
| Text::LineFold versions through 2019.001 for Perl duplicate the
| output based on the number of special break characters.
| Text::LineFold splits the input string by specific line break
| characters (such as VT, FF and others) into segments, but applies
| the break function to the entire string, not just the segment.  A
| side effect of this is that the full input can be duplicated for
| each segment.  Besides being incorrect, this can lead to unexpected
| resource consumption and possible denial of service.  Note that
| Text::LineFold is part of the Unicode-LineBreak distribution, which
| may have a higher version number than the module.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-8594
https://www.cve.org/CVERecord?id=CVE-2026-8594
[1] https://lists.security.metacpan.org/cve-announce/msg/40542383/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1138649#10
Date:
2026-07-18 05:18:40 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libunicode-linebreak-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138649@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emmanuel Bouthenot <kolter@debian.org> (supplier of updated libunicode-linebreak-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 18 Jul 2026 06:35:53 +0200
Source: libunicode-linebreak-perl
Architecture: source
Version: 0.0.20190101-4
Distribution: unstable
Urgency: medium
Maintainer: Emmanuel Bouthenot <kolter@debian.org>
Changed-By: Emmanuel Bouthenot <kolter@debian.org>
Closes: 1138649
Changes:
 libunicode-linebreak-perl (0.0.20190101-4) unstable; urgency=medium
 .
   * Add a patch to fix CVE-2016-1238 (unexpected resource consumption and
     possible denial of service) (Closes: #1138649)
   * Refresh lintian overrides
   * Bump Standards-Version to 4.7.4
   * Switch debhelper compatibility to 14
Checksums-Sha1:
 afb80da7eca8f2df1f054316c8432b8bf5fdada1 2201 libunicode-linebreak-perl_0.0.20190101-4.dsc
 cabc0e967574efe517ff96ff2e680a9a1fed9bbc 20408 libunicode-linebreak-perl_0.0.20190101-4.debian.tar.xz
 67015e2955dfe8254b1f84eec963c5f36b29db76 7556 libunicode-linebreak-perl_0.0.20190101-4_source.buildinfo
Checksums-Sha256:
 c19f092d1cd8ec153af8290e4b3f71c13bae6be934c9e317ae8a3314261b7e81 2201 libunicode-linebreak-perl_0.0.20190101-4.dsc
 0eb7159e5664b237432545f93a5112158d9c5992088b1d0cb4ad549fffe8a639 20408 libunicode-linebreak-perl_0.0.20190101-4.debian.tar.xz
 29f57a8b4ded0c2236eab5139455342a6351c748d1a9d4477c136c5c4a7a8ff4 7556 libunicode-linebreak-perl_0.0.20190101-4_source.buildinfo
Files:
 3d5c96c7d96755d96ea3736740a292e3 2201 perl optional libunicode-linebreak-perl_0.0.20190101-4.dsc
 ed03cf0b32b1f96697b53c472c60e05e 20408 perl optional libunicode-linebreak-perl_0.0.20190101-4.debian.tar.xz
 cfa538843338944e784492d5047e0a37 7556 perl optional libunicode-linebreak-perl_0.0.20190101-4_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQ1Tfow3vJnf8QuHSwd3I5KdQsMFAmpbB4UACgkQSwd3I5Kd
QsMb8Q/9EoOhz1BX8CZW0Eka2565389mHG0OLIhB0q0+KOfTg8FFD/4cOvgUVi8Y
/UahEfazrr4UcQbmFBVCJQS3G+7GiE7a84wYqwE2glMWBt/4FZGJBVMZveTYosUL
UT0Nju8twwPXbsoZT8BP5pQUnLXx7VyFnsZYjJxwggpKIZ9MrNJl+HnzEbrtM450
GeksZ6oSXSyxNgsb4UrOea/0eIgDL6oHlUHVuJi5kCMB7L986zipHznwgFatujGz
Z9SzY7QE7fnOsLs9fTuCiFj8jmcYra79gNssxF0bXVyrHJmmqNy59pWU6ioaT5Ao
IIWctIE36SxYVXlg2I7+i8DpxU+MZnV7v6/YCSNxXHRkORRcLQhzYEUOjb03pRQt
SHdo0p3MrslFXpVWPfezcVf3LhWS7h/gq5w7Kl0dJE05HqnV4rb7cQWnRgaYaNdv
IAn1UcBU0KlaAxliwA70LeGWdkys5rTt01NM/XufhPgVhZUxcblTghgpMlZTNv+p
AHtGDlIfJfVTqo3WqRXV/9rZvh9cV+2QYVPt6lJLVIeiOfP+VkQ4WK5H/lt3W/3c
LNtO7vv+Peuj7DUy+FC+miw+6WJ3ipUEQqRVHnH5ZuQ8F78M4Qa6bb+N5G5bKvtP
iJ8jW4m6UGKjP8qTE9UkDgz0WR+7zPOb/KcJofayjVk2IBCTJWc=
=A9zW
-----END PGP SIGNATURE-----

#1138649#15
Date:
2026-07-18 05:32:41 UTC
From:
To:
Hi,

Thanks for fixing the issue. FWIW, the changelog entry got the wrong
CVE id, should have been CVE-2026-8594.

Regards,
Salvatore