Hi Debian Security Team,
The following CVEs are reported against the perl source package in Trixie and have no fix available at time of filing.
S.No
CVE
CVSS
Component
Issue
1
CVE-2026-57433
9.8
Storable
Signed integer overflow on SX_HOOK deserialization; crafted thaw() input panics the process
2
CVE-2026-12087
9.1
Socket
pack_ip_mreq_source() validates wrong argument length; heap out-of-bounds read up to 3 bytes
3
CVE-2026-13221
9.1
perl core (regex)
Alternation > 65535 branches overflows 16-bit trie field; silent false-positive/negative matches
4
CVE-2026-57432
8.4
perl core (pack/un
Integer overflow in S_measure_struct; large repeat count leaks heap memory to caller
5
CVE-2026-48959
7.5
IO::Uncompress
fastForward() compares offset digit count instead of offset value; CPU exhaustion on crafted zip
6
CVE-2026-48962
7.3
IO::Compress
File::GlobMapper runs caller-supplied output glob through eval STRING; arbitrary code execution
7
CVE-2026-48961
7.3
IO::Compress
zipdetails crashes on Info-ZIP Unix Extra Field with 8-byte UID/GID; undefined subroutine
8
CVE-2026-7017
7.1
HTTP::Tiny
Authorization/Cookie headers forwarded to cross-origin redirect targets without origin check
All eight CVEs show Fix Status: open on the Debian security tracker. Please provide patched packages for trixie.
Regards,
Ejas Ali