#1138860 Archive-Tar: CVE-2026-42496

Package:
perl
Source:
perl
Description:
Larry Wall's Practical Extraction and Report Language
Submitter:
Niko Tyni
Date:
2026-08-17 21:21:03 UTC
Severity:
normal
Tags:
#1138860#5
Date:
2026-06-04 20:00:50 UTC
From:
To:
Package: perl
Version: 5.40.1-6
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org
Forwarded: https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158
Control: found -1 5.32.1-4
Control: found -1 5.36.0-1
Control: found -1 5.42.2-1

The following vulnerability was published[0] for Archive-Tar (bundled with perl):

  CVE ID:  CVE-2026-42496
  Distribution:  Archive-Tar
  Versions:  before 3.08

  MetaCPAN:  https://metacpan.org/dist/Archive-Tar
  VCS Repo:  https://github.com/jib/archive-tar-new

  Archive::Tar versions before 3.08 for Perl extract symlinks with
  attacker controlled targets outside the extraction directory

  Description
  -----------
  Archive::Tar versions before 3.08 for Perl extract symlinks with
  attacker controlled targets outside the extraction directory.

  _make_special_file() passes the tar header's linkname to symlink()
  without validating it against absolute paths or .. segments. The
  secure-extract mode check that guards regular file extraction does not
  cover the symlink target.

  A subsequent open through the extracted name reads or writes the
  attacker chosen path.

[0] https://lists.security.metacpan.org/cve-announce/msg/40396459/

#1138860#16
Date:
2026-06-05 18:46:14 UTC
From:
To:
I'm postponing fixes for CVE-2026-42496, CVE-2026-42497, and CVE-2026-9538
in Archive-Tar.

These are rather intertwined, and backporting them onto older versions
is pretty much the same thing as upgrading the whole module.

Also there's a regression fix in Archive-Tar 3.12 and I want to wait a bit
to see if others surface.

Upstream plans to include the fixes in point releases for 5.42 and 5.40,
as discussed in https://github.com/Perl/perl5/issues/24445 . Let's see
what they do with this first.

#1138860#21
Date:
2026-06-05 19:40:28 UTC
From:
To:
Hi Niko,

Sounds good, thanks for the update on those!

Regards,
Salvatore

#1138860#26
Date:
2026-07-03 15:31:54 UTC
From:
To:
While testing Perl-5.44.0-RC1, I noticed that libmodule-cpants-analyse-perl
will need an update to keep it building after this.

See https://github.com/Perl/perl5/issues/24452

#1138860#31
Date:
2026-08-03 18:00:19 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138860@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Niko Tyni <ntyni@debian.org> (supplier of updated perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 01 Aug 2026 16:13:58 +0300
Binary: libperl5.44 libperl-dev perl perl-base perl-debug perl-doc perl-modules-5.44
Source: perl
Architecture: all amd64 source
Version: 5.44.0-1
Distribution: experimental
Urgency: medium
Maintainer: Niko Tyni <ntyni@debian.org>
Changed-By: Niko Tyni <ntyni@debian.org>
Closes: 1138859 1138860 1138861 1140152 1141639 1142037
Description:
 libperl5.44 - shared Perl library
 libperl-dev - Perl library: development files
 perl-base  - minimal Perl system
 perl-debug - debug-enabled Perl interpreter
 perl-doc   - Perl documentation
 perl       - Larry Wall's Practical Extraction and Report Language
 perl-modules-5.44 - Core Perl modules
Changes:
 perl (5.44.0-1) experimental; urgency=medium
 .
   * Update to new upstream version 5.44.0.
   * [SECURITY] includes various upstream fixes:
     + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.
         (Closes: #1141639)
     + CVE-2026-42496: Archive::Tar symlink extraction.
         (Closes: #1138860)
     + CVE-2026-42497: Archive::Tar hardlink extraction.
         (Closes: #1138859)
     + CVE-2026-9538: Archive::Tar memory exhaustion.
         (Closes: #1138861)
     + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.
         (Closes: #1140152)
     + CVE-2026-13221: silently incorrect regular expression matches.
         (Closes: #1142037)
Checksums-Sha1:
 52da9fdc1cede54d5c3fac22d90954ac89e18eec 2372 perl_5.44.0-1.dsc
 1af3f3e6f0828e75f36ffaf50541a42a2bd33876 422344 perl_5.44.0.orig-regen-configure.tar.xz
 f64277b1a19107491ebd59249a33b7ea986eadd4 14919940 perl_5.44.0.orig.tar.xz
 a9ae4a664ce09fba56591033c23113ef3672969b 167824 perl_5.44.0-1.debian.tar.xz
 5d0c6091ad6aa1e647e157fd0a11e02df1aedefc 1169872 libperl-dev_5.44.0-1_amd64.deb
 d5dd071615b15af9caafa6db11d10eeaab1666fc 4314308 libperl5.44_5.44.0-1_amd64.deb
 1241cdb2d398f534a9f191edc5ca3d1edeed0690 1893660 perl-base_5.44.0-1_amd64.deb
 4a8f2da10bd3820e9d67e119b6ca4a8e03694b7d 14229824 perl-debug_5.44.0-1_amd64.deb
 b2e68ee0be61249b82f6023cb437235ed93bdbad 8632296 perl-doc_5.44.0-1_all.deb
 5e059124d30cc540a7122d5f534bf64ed7cd80ae 3264904 perl-modules-5.44_5.44.0-1_all.deb
 3b41d7b0ef18f03e8282fa154a4f1dd8ee56b581 6788 perl_5.44.0-1_amd64.buildinfo
 f00bc2d862927b8f02a8477412d07baec1178618 267456 perl_5.44.0-1_amd64.deb
Checksums-Sha256:
 c350428472e7325f1f4c675f8b8884bc308f493bc16b01481b54cee7e23acc2b 2372 perl_5.44.0-1.dsc
 82e0dcddac1dd15c4078c969628533f587a31f4e229824763cbd84ab4db628e1 422344 perl_5.44.0.orig-regen-configure.tar.xz
 505cf43912e9480495c344c70260452e32aa2a73c546a026b3f100053b23ce91 14919940 perl_5.44.0.orig.tar.xz
 033db6f3304e21fc74244cd8f266a4c503aa4f69550628175598bb55215c66fa 167824 perl_5.44.0-1.debian.tar.xz
 42442899b17837421b14ca9c4a88f7a03469fc94ac814fe338117b20206b4a51 1169872 libperl-dev_5.44.0-1_amd64.deb
 8c42c564e01a264c3c219f6a67edc4c650c6d569e099832cd2e7f8df67d40aeb 4314308 libperl5.44_5.44.0-1_amd64.deb
 9e8b4cacdf5cc0b83c615a2a70e2f31d58f0b5e4cf60d84ef9ee00bc6fb16525 1893660 perl-base_5.44.0-1_amd64.deb
 8fb0f5bc5fdfe6e8f1e00cf7806fe1ca9c30094c1e5aeb6e1a4d51fc69f9a47a 14229824 perl-debug_5.44.0-1_amd64.deb
 629e51f6e08333f15d4db4133063cca0296d4254d4278baeacc6ee81018db18f 8632296 perl-doc_5.44.0-1_all.deb
 3bb613760a3124e27812f1cb465e694c4fa16a2ab2e6e6cb995b629f2c302cbd 3264904 perl-modules-5.44_5.44.0-1_all.deb
 33c02cc931ec81e38d826cfd5563f281d6effae48894e3c1c0c3a397e426a6e2 6788 perl_5.44.0-1_amd64.buildinfo
 de083313f83e1f0a91dd3b2d0eacb300736fa57da075be75d06e05b3f77dff9a 267456 perl_5.44.0-1_amd64.deb
Files:
 b74f725330b7a8c1022d5a0a094b50ba 2372 perl standard perl_5.44.0-1.dsc
 dad7233fa6f18a19cb9a9afb90e4f4ad 422344 perl standard perl_5.44.0.orig-regen-configure.tar.xz
 55761cf1543af326492fd194647796d1 14919940 perl standard perl_5.44.0.orig.tar.xz
 aa94d0156a03a38a1f064018f2fb5767 167824 perl standard perl_5.44.0-1.debian.tar.xz
 802b65b732c978e6c2a94893e0e23632 1169872 libdevel optional libperl-dev_5.44.0-1_amd64.deb
 9283ba15150c8e920f382d55278dcad0 4314308 libs optional libperl5.44_5.44.0-1_amd64.deb
 b738fa4f8077293033032235bd281a7c 1893660 perl required perl-base_5.44.0-1_amd64.deb
 a01ea1c2408ee889bd2dde7e417555ba 14229824 devel optional perl-debug_5.44.0-1_amd64.deb
 c94b049c24d91106a4202e4afa646d8b 8632296 doc optional perl-doc_5.44.0-1_all.deb
 c31d62cfa1c2ccbde8639ba340673dc3 3264904 libs optional perl-modules-5.44_5.44.0-1_all.deb
 c12a01537609245f9e00c3d2af30779d 6788 perl standard perl_5.44.0-1_amd64.buildinfo
 cd0ad89ed14646911c8a9225251a9cc8 267456 perl standard perl_5.44.0-1_amd64.deb
-----BEGIN PGP SIGNATURE-----

iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCam4S8xEcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5skM0AYDaZL3Z9ilbu6MeQXc46svSz/aTZA1kz7aT
CQClJPQ80M311fKlz++6StNrHFHZMtUBegPC6+lzUsn6NzPb10c9KyfPU4Y6iypz
sDjehkY+t0ddeZURsMw7dhEww8f2dZbcSQ==
=AZ4Z
-----END PGP SIGNATURE-----

#1138860#38
Date:
2026-08-17 21:19:13 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138860@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Niko Tyni <ntyni@debian.org> (supplier of updated perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 17 Aug 2026 22:59:18 +0300
Source: perl
Architecture: source
Version: 5.42.3-1
Distribution: unstable
Urgency: medium
Maintainer: Niko Tyni <ntyni@debian.org>
Changed-By: Niko Tyni <ntyni@debian.org>
Closes: 1138859 1138860 1138861 1140152 1141639 1142037
Changes:
 perl (5.42.3-1) unstable; urgency=medium
 .
   * Update to new upstream version 5.42.3.
   * [SECURITY] includes various upstream fixes:
     + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.
         (Closes: #1141639)
     + CVE-2026-9538: Archive::Tar memory exhaustion.
         (Closes: #1138861)
     + CVE-2026-42496: Archive::Tar symlink extraction.
         (Closes: #1138860)
     + CVE-2026-42497: Archive::Tar hardlink extraction.
         (Closes: #1138859)
     + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.
         (Closes: #1140152)
     + CVE-2026-13221: silently incorrect regular expression matches.
         (Closes: #1142037)
   * Refresh cross support files for all architectures.
     + also update the architecture lists in d/cross/README
   * Disable salsa-ci.yml as nobody currently cares about the results.
   * Update debian/copyright based on DFSG team review.
Checksums-Sha1:
 a312494e84f08a1bd4a29edeae6dd7af59e06b1c 2372 perl_5.42.3-1.dsc
 1dcede801d09bd47ad351fb4d6280edd879772ed 421372 perl_5.42.3.orig-regen-configure.tar.xz
 1d878802a55eacc778bb1d84b1f1b8ab9b22cc96 14495300 perl_5.42.3.orig.tar.xz
 5d3bc13b5f9b7b0a8093a466e26f37003c922a34 168064 perl_5.42.3-1.debian.tar.xz
 c533e6406fe5a3ab42f5a5814a4f5bbe61fc0435 5338 perl_5.42.3-1_source.buildinfo
Checksums-Sha256:
 36535968b24b1f73ce1cf980208017dbe4a38bff5b501cd752e82139206282f7 2372 perl_5.42.3-1.dsc
 5ae2aea5bc800c05324e4c9b166391b17368d10300c036fbe45f8c23a799c355 421372 perl_5.42.3.orig-regen-configure.tar.xz
 c9387e1473a1866935cb047ece7c2e0a80767a3acdecb79d4a375f8a95970ddc 14495300 perl_5.42.3.orig.tar.xz
 0b5692654b3efe8be7e469be851ac8abf6a425bba7c2be5a29a0d553a450956f 168064 perl_5.42.3-1.debian.tar.xz
 71408f9f725faa3539ed2d98c1b0f269a4f4d8064daebd44cb891fa0aff2cee4 5338 perl_5.42.3-1_source.buildinfo
Files:
 20b760b76e6048cab15d794225bbb2fb 2372 perl standard perl_5.42.3-1.dsc
 78cfa5d6df88d464bb118092b5722419 421372 perl standard perl_5.42.3.orig-regen-configure.tar.xz
 fb96e6cf064bf374e84ef232b0eda5c1 14495300 perl standard perl_5.42.3.orig.tar.xz
 c03a130c2f86e55c9eb492a835f0a4cf 168064 perl standard perl_5.42.3-1.debian.tar.xz
 1ac4284e689b699f60caca7504d2e3e7 5338 perl standard perl_5.42.3-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCaoNvcxEcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5srEgAX0RXoXPd0TqEsji+TWA40DTRHIvi9ctyYY/
QA5rNIMgACSGInRTA9LfgfGxHVz828IBgK4HCkE8j9XTfT5LwEGP2a0kwmoCEULu
U9DCNBdol5tJx8F0xbiRPCADcrM7ZZAxhg==
=GdB3
-----END PGP SIGNATURE-----