Hi, The following vulnerability was published for perl. CVE-2026-57432[0]: | Perl versions through 5.43.10 have an integer overflow in | S_measure_struct leading to an out-of-bounds heap read in pack and | unpack. S_measure_struct adds each item's size times its repeat | count to a running total with no overflow check, so a large repeat | count in a pack or unpack template wraps the signed SSize_t total | negative. The @, X, and x position codes then guard their moves with | a signed length comparison that passes when the length is negative, | advancing the buffer pointer out of bounds. A template derived from | untrusted input can read heap memory past the buffer and return it | to the caller. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-57432 https://www.cve.org/CVERecord?id=CVE-2026-57432 [1] https://lists.security.metacpan.org/cve-announce/msg/41780102/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Control: unarchive 1138905 Control: retitle 1138905 perl: CVE-2026-57432: integer overflow in S_measure_struct Control: forcemerge 1138905 -1 This is #1138905, already fixed in testing/unstable (but not in stable so far.) So merging.
Hi Niko, Samewise here, sorry for that. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1138905@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Niko Tyni <ntyni@debian.org> (supplier of updated perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 30 Aug 2026 11:53:55 +0300
Source: perl
Architecture: source
Version: 5.40.1-6+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Niko Tyni <ntyni@debian.org>
Changed-By: Niko Tyni <ntyni@debian.org>
Closes: 1137345 1138854 1138855 1138856 1138858 1138859 1138860 1138863 1138905 1138906 1140152 1141639 1142037
Changes:
perl (5.40.1-6+deb13u1) trixie; urgency=medium
.
* [SECURITY] various upstream fixes:
+ CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.
(Closes: #1141639)
+ CVE-2026-42496: Archive::Tar symlink extraction.
(Closes: #1138860)
+ CVE-2026-42497: Archive::Tar hardlink extraction.
(Closes: #1138859)
+ CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.
(Closes: #1140152)
+ CVE-2026-13221: silently incorrect regular expression matches.
(Closes: #1142037)
+ CVE-2025-15649: header parsing in IO::Uncompress::Unzip.
(Closes: #1138863)
+ CVE-2026-7010: CRLF-validation in HTTP::Tiny.
(Closes: #1138858)
+ CVE-2026-8376: Buffer overflow in Perl_study_chunk.
(Closes: #1137345)
+ CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.
(Closes: #1138856)
+ CVE-2026-48961: crash in zipdetails.
(Closes: #1138855)
+ CVE-2026-48962: code execution in IO-Compress via output globs.
(Closes: #1138854)
+ CVE-2026-57432: out of bound heap reads in pack() and unpack().
(Closes: #1138905)
+ CVE-2026-57433: signed integer overflow in Storable.
(Closes: #1138906)
Checksums-Sha1:
735f1a33e381a4037b22f895726d2ffce281b39a 2404 perl_5.40.1-6+deb13u1.dsc
1c181a089b69ccda8f7adce847dd5d8984e247a7 186360 perl_5.40.1-6+deb13u1.debian.tar.xz
ea71ff39ab625af81797eabf49136bbde5cba4d6 5370 perl_5.40.1-6+deb13u1_source.buildinfo
Checksums-Sha256:
92d1cfb32167d77fada7284f1c291de72f93eb896f5cfd58247d020182b403a8 2404 perl_5.40.1-6+deb13u1.dsc
5ee76db601d6f4638433ab9b0f5bd5cfb15b102a79d902ff282e762becb7e724 186360 perl_5.40.1-6+deb13u1.debian.tar.xz
1d89f7d92719f484d03265fcb34f83604a133e8881dd316e5d0f3d5f123fc556 5370 perl_5.40.1-6+deb13u1_source.buildinfo
Files:
7a19d8c54c89ea059a709d4aaa11ddef 2404 perl standard perl_5.40.1-6+deb13u1.dsc
25a497217f31c1bd9abec448d442a144 186360 perl standard perl_5.40.1-6+deb13u1.debian.tar.xz
d4d9e67ab46dd7c539b74461b14e7aa5 5370 perl standard perl_5.40.1-6+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCaphfzREcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5sgacAYCoZbN23QhO+v2JfNcanwF/DXR/IxDBIVbz
wr0rQgPWbzmq5KXCXgA4BZ/Wp5+unkQBf1v9bOahz673IgWB1C/XGwZ7jUDHEVcJ
yxs3NFuIerDHvhsPIkaDw83nFiQsm/BdeQ==
=xXL0
-----END PGP SIGNATURE-----