#1144498 perl: 8 unpatched security CVEs - request fix for trixie

Package:
perl
Source:
perl
Description:
Larry Wall's Practical Extraction and Report Language
Submitter:
Mohammad, Ejas Ali
Date:
2026-08-16 12:03:02 UTC
Severity:
normal
#1144498#5
Date:
2026-08-16 07:33:45 UTC
From:
To:
Hi Debian Security Team,

The following CVEs are reported against the perl source package in Trixie and have no fix available at time of filing.

S.No
CVE
CVSS
Component
Issue
1
CVE-2026-57433
9.8
Storable
Signed integer overflow on SX_HOOK deserialization; crafted thaw() input panics the process
2
CVE-2026-12087
9.1
Socket
pack_ip_mreq_source() validates wrong argument length; heap out-of-bounds read up to 3 bytes
3
CVE-2026-13221
9.1
perl core (regex)
Alternation > 65535 branches overflows 16-bit trie field; silent false-positive/negative matches
4
CVE-2026-57432
8.4
perl core (pack/un
Integer overflow in S_measure_struct; large repeat count leaks heap memory to caller
5
CVE-2026-48959
7.5
IO::Uncompress
fastForward() compares offset digit count instead of offset value; CPU exhaustion on crafted zip
6
CVE-2026-48962
7.3
IO::Compress
File::GlobMapper runs caller-supplied output glob through eval STRING; arbitrary code execution
7
CVE-2026-48961
7.3
IO::Compress
zipdetails crashes on Info-ZIP Unix Extra Field with 8-byte UID/GID; undefined subroutine
8
CVE-2026-7017
7.1
HTTP::Tiny
Authorization/Cookie headers forwarded to cross-origin redirect targets without origin check

All eight CVEs show Fix Status: open on the Debian security tracker. Please provide patched packages for trixie.

Regards,
Ejas Ali

#1144498#10
Date:
2026-08-16 12:00:05 UTC
From:
To:
There are already bugs filed for these CVEs, and as you say they are
tracked in the security tracker.

There is no need for an additional bug to keep track of the work. Closing this one.

I assume this was not an offer of a tested package that is ready for
trixie-security?

Best,
Chris