[CLSA-2026:1784295790] Fix CVE(s): CVE-2026-13221, CVE-2026-57432
Type:
security
Severity:
Critical
Release date:
2026-07-17 13:43:39 UTC
Description:
* SECURITY UPDATE: silently incorrect regular expression matches from oversized tries - debian/patches/CVE-2026-13221.patch: skip building a trie when the delta between the first branch and the shared tail would overflow the 16-bit next_off field in S_study_chunk() in regcomp.c; add a regression test in t/re/pat_advanced.t; backported from upstream commit 03f74bbbd3a68350d926ee93d56ee4808c28c4c7. - CVE-2026-13221 * SECURITY UPDATE: out-of-bounds heap read in pack/unpack - debian/patches/CVE-2026-57432.patch: croak when the computed structure size would overflow SSize_t and harden the B/b and H/h length calculations in S_measure_struct() in pp_pack.c; document the new diagnostic in pod/perldiag.pod; backported from upstream commits 5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 and 40754edc72dd3e513d758153c0e2f0215897740e. - CVE-2026-57432
Updated packages:
  • libperl-dev_5.30.0-9ubuntu0.5+tuxcare.els3_amd64.deb
    sha:99a020dc20aaea33fb3246660d627510fdac0de6
  • libperl5.30_5.30.0-9ubuntu0.5+tuxcare.els3_amd64.deb
    sha:eb442aa222a0ffd65dc42b5c860cb76eb55c293d
  • perl_5.30.0-9ubuntu0.5+tuxcare.els3_amd64.deb
    sha:360ab660a45dcda6bc03edd561ba99f73ce2f237
  • perl-base_5.30.0-9ubuntu0.5+tuxcare.els3_amd64.deb
    sha:793689f136e6349b1c0950f66005209ee588f448
  • perl-debug_5.30.0-9ubuntu0.5+tuxcare.els3_amd64.deb
    sha:c9f4a76eef1e0ed8dfc08e517378c52a660622b6
  • perl-doc_5.30.0-9ubuntu0.5+tuxcare.els3_all.deb
    sha:902ca0d71b0f13cad8f18f8883b677fe8d69d280
  • perl-modules-5.30_5.30.0-9ubuntu0.5+tuxcare.els3_all.deb
    sha:1dfd09437ec5430785dacd4bf08b5764a1b6b82a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.