[ Reason ]
This fixes CVE-2026-19566, a minor input sanitizing fix. It's a
followup to CVE-2026-49942, which was not complete.
[ Impact ]
Depending on the usage of the library this may be a security issue.
[ Tests ]
salsa-ci passed execpt test-uscan (which isn't a problem for a
trixie-pu). See
https://salsa.debian.org/perl-team/modules/packages/libnet-cidr-set-perl/-/pipelines/1177382
The patches ships its own test cases, which succeed.
[ Risks ]
Hopefully none...
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in stable
[x] the issue is verified as fixed in unstable
[ Changes ]
Minimal fix for CVE-2026-19566 including a new test case.
[ Other info ]
According to
https://security-tracker.debian.org/tracker/CVE-2026-19566 this is a
minor issue, so it's not for DSA but for a point release.
Greetings
Roland