#1142227 libxml-bare-perl: CVE-2026-13401 CVE-2026-57074

Package:
src:libxml-bare-perl
Source:
src:libxml-bare-perl
Submitter:
Salvatore Bonaccorso
Date:
2026-07-16 21:20:02 UTC
Severity:
normal
Tags:
#1142227#5
Date:
2026-07-16 18:36:15 UTC
From:
To:
Hi,

The following vulnerabilities were published for libxml-bare-perl.

CVE-2026-13401[0]:
| XML::Bare versions through 0.53 for Perl will hang in an infinite
| loop when parsing malformed attributes.  The parserc_parse function
| never advances the attribute-parse state cursor on certain malformed
| attribute forms, looping forever.  Nameless attributes such as "<a
| ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this
| condition.


CVE-2026-57074[1]:
| XML::Bare versions through 0.53 for Perl have an unbounded character
| lookahead.  The parserc_parse function attempts to check for
| multicharacter strings such as "<![CDATA" or element terminators
| such as ">" without checking that the offsets are within the buffer.
| Truncated strings such as "<a/" can trigger an out-of-bounds read.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-13401
https://www.cve.org/CVERecord?id=CVE-2026-13401
[1] https://security-tracker.debian.org/tracker/CVE-2026-57074
https://www.cve.org/CVERecord?id=CVE-2026-57074

Regards,
Salvatore

#1142227#12
Date:
2026-07-16 21:05:43 UTC
From:
To:
Hello,

Bug #1142227 in libxml-bare-perl reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/perl-team/modules/packages/libxml-bare-perl/-/commit/832e5fc6e06dc82630d1b545b3381c73530f374e
------------------------------------------------------------------------
Add patches to fix CVE-2026-13401 and CVE-2026-57074.

Closes: #1142227
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142227

#1142227#19
Date:
2026-07-16 21:18:59 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libxml-bare-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142227@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libxml-bare-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 16 Jul 2026 22:57:26 +0200
Source: libxml-bare-perl
Architecture: source
Version: 0.53-5
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1142227
Changes:
 libxml-bare-perl (0.53-5) unstable; urgency=medium
 .
   * Add patches to fix CVE-2026-13401 and CVE-2026-57074.
     (Closes: #1142227)
   * Update years of packaging copyright.
   * Declare compliance with Debian Policy 4.7.4.
   * Remove «Rules-Requires-Root: no», which is the current default.
   * Remove «Priority: optional», which is the current default.
Checksums-Sha1:
 b2f11a22d3222be9c7f71cbe5139fad5f7bfbfa3 2361 libxml-bare-perl_0.53-5.dsc
 b4c21832ad5686570ab43543ef4162b09f859f29 6788 libxml-bare-perl_0.53-5.debian.tar.xz
Checksums-Sha256:
 270f08ed74dd2dcade139f715ca7faf8c19aaf665e2cf1cdf5d4b72e85f1503d 2361 libxml-bare-perl_0.53-5.dsc
 6ffa29a6c79266c3de980595c566b10050b7c38a4b925b1cac0ef3b967524d43 6788 libxml-bare-perl_0.53-5.debian.tar.xz
Files:
 27e9ef45e1596fb186bee26061e58cec 2361 perl optional libxml-bare-perl_0.53-5.dsc
 ac5487482f6b3505ac3bd3cd19bee8c2 6788 perl optional libxml-bare-perl_0.53-5.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpZRwFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgacew/+PfTDCqMcYcu3ofHVI3AlPpv4PcrQDGWZdf3g+bJZVyq4sLK/xLGluk4g
CVzq02wLhxbGO4Y7VeUpgW2+zdX7lIITxIvxx8EeUPfE8Vnw7C9rXqae4L8cGmvr
+4/Npwcvoq+JQIDdDEFcJR9XegIrq1kR3SL5ToLt8fcV7XrT226KlSnmAB6Uozr+
/w2R/juyysf1VxtLmKO4lfyDpWdevl4U2DVuDJ9sb9ZTflKVydx4a3cJurxs+LCk
rGx8iDbsVFadFV5wbF4OZcrLFI6Q7qqWxXQACbAiDtRbVoXWQnANlo6vxutWyFEW
3EEqUctly+tpN2Yb36Slf4Z7STkhexkX+1XHRK50UXNVSgGnYFIn2x8niV1OOcVJ
m8G5rQjED7VzMUCreDUQS3iryLxeLZZDCazxpbZGEZBXxDCz81t9EKJWe6yU2ghq
QZjuScftEdmFBq3uKUXxfD3IIlN0wCQdRkH0b5xTMUisGgKOrQFHFcTXfsYZtlZc
m/uf4h3/DIRdeKw8JvvCkklTL0DTvN3kY/HtaOlVAMf+mnfF2jNjv7OYYHNyF8Tc
6ql2b1Cfu5hKgVkvi9Aj1lSdPscuVKSZ6Evt3K7IzeVgYw7XSlL7ERmMiRGMqtxF
Rrx3Uh7lE/Nu9dJ1kDBVowcE7FAwY0Nb8cJHln2jyAFxlJNosTQ=
=Cmw+
-----END PGP SIGNATURE-----