[ubuntu/noble-security] perl 5.38.2-3.2ubuntu0.3 (Accepted)

Chrisa Oikonomou chrisa.oikonomou at canonical.com
Wed Jun 24 11:48:15 UTC 2026


perl (5.38.2-3.2ubuntu0.3) noble-security; urgency=high

  * SECURITY UPDATE: path traversal in Archive::Tar symlink/hardlink extraction
    - debian/patches/CVE-2026-42496.patch: validate symlink and hardlink
      targets against absolute paths and directory traversal in
      cpan/Archive-Tar/lib/Archive/Tar.pm
    - CVE-2026-42496
  * SECURITY UPDATE: integer overflow in regular expression compiler
    - debian/patches/CVE-2026-8376_1.patch: add test cases for heap buffer
      overflow via quantified fixed-string regex in t/re/pat_psycho.t
    - debian/patches/CVE-2026-8376_2.patch: add overflow check before
      fixed-string buffer allocation in regcomp.c / regcomp_study.c
    - CVE-2026-8376

Date: 2026-06-22 15:25:15.948039+00:00
Changed-By: Chrisa Oikonomou <chrisa.oikonomou at canonical.com>
https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list