[ubuntu/jammy-security] perl 5.34.0-3ubuntu1.7 (Accepted)

Chrisa Oikonomou chrisa.oikonomou at canonical.com
Wed Jun 24 11:48:15 UTC 2026


perl (5.34.0-3ubuntu1.7) jammy-security; urgency=high

  * SECURITY UPDATE: integer overflow in regular expression compiler
    - debian/patches/CVE-2026-8376_1.patch: accept quantifier limit error
      on 32-bit architectures where the quantifier limit catches the
      oversized pattern before the overflow guard
    - CVE-2026-8376

perl (5.34.0-3ubuntu1.6) jammy-security; urgency=high

  * SECURITY UPDATE: path traversal in Archive::Tar symlink/hardlink extraction
    - debian/patches/CVE-2026-42496.patch: validate symlink and hardlink
      targets against absolute paths and directory traversal in
      cpan/Archive-Tar/lib/Archive/Tar.pm
    - CVE-2026-42496
  * SECURITY UPDATE: integer overflow in regular expression compiler
    - debian/patches/CVE-2026-8376_1.patch: add test cases for heap buffer
      overflow via quantified fixed-string regex in t/re/pat_psycho.t
    - debian/patches/CVE-2026-8376_2.patch: add overflow check before
      fixed-string buffer allocation in regcomp.c / regcomp_study.c
    - CVE-2026-8376

Date: 2026-06-23 10:17:12.148949+00:00
Changed-By: Chrisa Oikonomou <chrisa.oikonomou at canonical.com>
https://launchpad.net/ubuntu/+source/perl/5.34.0-3ubuntu1.7
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list