[ubuntu/jammy-security] perl 5.34.0-3ubuntu1.7 (Accepted)
Chrisa Oikonomou
chrisa.oikonomou at canonical.com
Wed Jun 24 11:48:15 UTC 2026
perl (5.34.0-3ubuntu1.7) jammy-security; urgency=high
* SECURITY UPDATE: integer overflow in regular expression compiler
- debian/patches/CVE-2026-8376_1.patch: accept quantifier limit error
on 32-bit architectures where the quantifier limit catches the
oversized pattern before the overflow guard
- CVE-2026-8376
perl (5.34.0-3ubuntu1.6) jammy-security; urgency=high
* SECURITY UPDATE: path traversal in Archive::Tar symlink/hardlink extraction
- debian/patches/CVE-2026-42496.patch: validate symlink and hardlink
targets against absolute paths and directory traversal in
cpan/Archive-Tar/lib/Archive/Tar.pm
- CVE-2026-42496
* SECURITY UPDATE: integer overflow in regular expression compiler
- debian/patches/CVE-2026-8376_1.patch: add test cases for heap buffer
overflow via quantified fixed-string regex in t/re/pat_psycho.t
- debian/patches/CVE-2026-8376_2.patch: add overflow check before
fixed-string buffer allocation in regcomp.c / regcomp_study.c
- CVE-2026-8376
Date: 2026-06-23 10:17:12.148949+00:00
Changed-By: Chrisa Oikonomou <chrisa.oikonomou at canonical.com>
https://launchpad.net/ubuntu/+source/perl/5.34.0-3ubuntu1.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list