Your message dated Mon, 20 Jul 2026 21:04:36 +0000
with message-id <[email protected]>
and subject line Bug#1142503: fixed in libnet-dns-perl 1.56-1
has caused the Debian Bug report #1142503,
regarding libnet-dns-perl: CVE-2026-64193 CVE-2026-64194
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142503: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142503
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libnet-dns-perl
Version: 1.55-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for libnet-dns-perl.

CVE-2026-64193[0]:
| Net::DNS versions through 1.55 for Perl allow remote execution
| injection via EDNS EXTENDED ERROR.
| Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT
| field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the
| raw bytes and passing the result to Perl's eval. There is some
| escaping done for $ and @, but not for backticks. This can be
| exploited for command execution if $pkt->edns->option('EXTENDED-
| ERROR') is called in array context, for example with a payload of
| {0:`"<command>"`} in EXTRA-TEXT.


CVE-2026-64194[1]:
| Net::DNS versions through 1.55 for Perl allow Denial of Service via
| deep DNS compression pointer chains.  Net::DNS::DomainName::decode
| follows RFC 1035 compression pointers by recursing into itself with
| no depth limit. It is possible to construct a name which saturates
| the call stack (at least with larger TCP responses), leading to a
| potential Denial of Service.  The guard `$link < $offset` prevents
| forward and circular chains, but still allows arbitrarily long
| backward chains. The per-offset cache (`$cache`) is populated at the
| start of each call and short-circuits only re-traverses of the same
| offset - the initial descent through a fresh chain still recurses at
| full depth.  A crafted packet can chain two-byte compression
| pointers so that each one points two bytes earlier than the
| previous, producing a chain length of `offset / 2`. For the 14-bit
| pointer field (max offset 16383) this gives up to ~8191 recursive
| frames. For a TCP DNS message the limit is the 16-bit length field
| (~32767 frames). Perl's default C stack handles only a few thousand
| frames; beyond that the process receives SIGSEGV or similar, which
| is a denial-of-service for any application parsing untrusted DNS
| data.  The vulnerability is triggered by
| `Net::DNS::Packet->new(\$wire)` i.e. any point where the library
| decodes a DNS message from the network.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-64193
    https://www.cve.org/CVERecord?id=CVE-2026-64193
[1] https://security-tracker.debian.org/tracker/CVE-2026-64194
    https://www.cve.org/CVERecord?id=CVE-2026-64194

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libnet-dns-perl
Source-Version: 1.56-1
Done: gregor herrmann <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libnet-dns-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
gregor herrmann <[email protected]> (supplier of updated libnet-dns-perl 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 20 Jul 2026 22:39:00 +0200
Source: libnet-dns-perl
Architecture: source
Version: 1.56-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <[email protected]>
Changed-By: gregor herrmann <[email protected]>
Closes: 1142503
Changes:
 libnet-dns-perl (1.56-1) unstable; urgency=medium
 .
   * Team upload.
   * Import upstream version 1.56.
     Includes fixes for CVE-2026-64193 and CVE-2026-64194.
     (Closes: #1142503)
Checksums-Sha1:
 748fe6ff1f8af78acff313a5d524517bfc7852aa 2710 libnet-dns-perl_1.56-1.dsc
 d90acd875d7ce46b636f93ef294d15180abebf11 266111 
libnet-dns-perl_1.56.orig.tar.gz
 2ef8f7ab7a19f4428b52524ad14ab934c3b90cc9 8592 
libnet-dns-perl_1.56-1.debian.tar.xz
Checksums-Sha256:
 3fa5e4fa73c1ecebd334d5737bca30d5fbbd33d344ff8c369795e7574b54707c 2710 
libnet-dns-perl_1.56-1.dsc
 5930e39f76895b380c7ca11fc08352d15ad71c41fe84c12dfb6a322d17f66946 266111 
libnet-dns-perl_1.56.orig.tar.gz
 8d4dfa6db2411679fef953e2b7b8e804ee34f7f38d5304eecf09a42b69f82af9 8592 
libnet-dns-perl_1.56-1.debian.tar.xz
Files:
 af33d951e10f114461aeee392a330be2 2710 perl optional libnet-dns-perl_1.56-1.dsc
 683b3e1d4882d242478e192b2579ae88 266111 perl optional 
libnet-dns-perl_1.56.orig.tar.gz
 e333c032c7a930891bd2b5399d909ad1 8592 perl optional 
libnet-dns-perl_1.56-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpeiAlfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgZQWg/8CSbMjkUxLEEr3Ss1qbnn/InAv7FMcavlgLW13331ND9Zu8RqgTwU2mIu
oHhDacs1lx1gbJHKDNXm8uY3uIQf/H38Us7tpiMT/cYonG64CKh/F8oRTFyZt811
1gqgynRXbFer6a0ngWk1ZXQCzzh6lUDmhHANds5IlGvhUuBGx2PuB4iPp+H+BkBE
eVpFaZefDDK3uQlypTYb6FliPBgRFiMzoOBCxodpUZ5yJgsuw+PMRr+QLx3v/AwD
elRTVI/HZc2kStH+FPkd0Q3YBF0b//CUA/kqolMJCeq0qrBjdzoRZX7KWWgU6Srj
oTLgnxoGjlchwy8ty4C/PrzX/1UFwCy09ZmJGxyjwduqwaUxztYB0L7CP7dLzEb6
yMT/aIRlfTdBiVomxlZ+QIZVOQVHjRqkwHh41xlKzJQvxLNfod/UJEqZnDETeyrY
hD69JsRCSDJW5HJmiD0Fm+29AOWXw/aU1h6hOZnpdhDdSROD3u6VRTizP8AA5Qwy
GBSc+WJ/3RRqGX8bjM8DluVHorF0i+PTii0bsfPiKW8GTYBdJwafqeN5Hf+P8wMT
uYx/eU4+sUJDRyc/n0E4PDEF2oBhIKFV8IVqbQEP2EEucNSxc5uYvtLZNAubp2pN
nk18GEGIGMwUySX76C2B6izQ58SlH1tYe0I5qp+h6QHjX+p/TgM=
=/uzD
-----END PGP SIGNATURE-----

Attachment: pgpEuz34go7Om.pgp
Description: PGP signature


--- End Message ---

Reply via email to