Your message dated Mon, 03 Aug 2026 18:00:19 +0000
with message-id <[email protected]>
and subject line Bug#1142037: fixed in perl 5.44.0-1
has caused the Debian Bug report #1142037,
regarding perl: CVE-2026-13221
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142037: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142037
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: perl
Version: 5.40.1-8
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for perl.
CVE-2026-13221[0]:
| Perl versions through 5.43.9 produce silently incorrect regular
| expression matches when an alternation of more than 65535 fixed
| string branches is compiled into a trie in Perl_study_chunk. When
| such branches are combined into a trie, the delta between the first
| branch and the shared tail is stored in a 16-bit field. A branch
| count above 65535 overflows the field, and the trie's match decision
| table is truncated with no warning or error. A pattern of this
| shape produces false positive matches (matching strings it should
| not) and false negative matches (failing to match strings it
| should). When such a pattern gates an access or filtering decision,
| the result is wrong.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-13221
https://www.cve.org/CVERecord?id=CVE-2026-13221
[1] https://lists.security.metacpan.org/cve-announce/msg/41780104/
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: perl
Source-Version: 5.44.0-1
Done: Niko Tyni <[email protected]>
We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Niko Tyni <[email protected]> (supplier of updated perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA384
Format: 1.8
Date: Sat, 01 Aug 2026 16:13:58 +0300
Binary: libperl5.44 libperl-dev perl perl-base perl-debug perl-doc
perl-modules-5.44
Source: perl
Architecture: all amd64 source
Version: 5.44.0-1
Distribution: experimental
Urgency: medium
Maintainer: Niko Tyni <[email protected]>
Changed-By: Niko Tyni <[email protected]>
Closes: 1138859 1138860 1138861 1140152 1141639 1142037
Description:
libperl5.44 - shared Perl library
libperl-dev - Perl library: development files
perl-base - minimal Perl system
perl-debug - debug-enabled Perl interpreter
perl-doc - Perl documentation
perl - Larry Wall's Practical Extraction and Report Language
perl-modules-5.44 - Core Perl modules
Changes:
perl (5.44.0-1) experimental; urgency=medium
.
* Update to new upstream version 5.44.0.
* [SECURITY] includes various upstream fixes:
+ CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.
(Closes: #1141639)
+ CVE-2026-42496: Archive::Tar symlink extraction.
(Closes: #1138860)
+ CVE-2026-42497: Archive::Tar hardlink extraction.
(Closes: #1138859)
+ CVE-2026-9538: Archive::Tar memory exhaustion.
(Closes: #1138861)
+ CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.
(Closes: #1140152)
+ CVE-2026-13221: silently incorrect regular expression matches.
(Closes: #1142037)
Checksums-Sha1:
52da9fdc1cede54d5c3fac22d90954ac89e18eec 2372 perl_5.44.0-1.dsc
1af3f3e6f0828e75f36ffaf50541a42a2bd33876 422344
perl_5.44.0.orig-regen-configure.tar.xz
f64277b1a19107491ebd59249a33b7ea986eadd4 14919940 perl_5.44.0.orig.tar.xz
a9ae4a664ce09fba56591033c23113ef3672969b 167824 perl_5.44.0-1.debian.tar.xz
5d0c6091ad6aa1e647e157fd0a11e02df1aedefc 1169872 libperl-dev_5.44.0-1_amd64.deb
d5dd071615b15af9caafa6db11d10eeaab1666fc 4314308 libperl5.44_5.44.0-1_amd64.deb
1241cdb2d398f534a9f191edc5ca3d1edeed0690 1893660 perl-base_5.44.0-1_amd64.deb
4a8f2da10bd3820e9d67e119b6ca4a8e03694b7d 14229824 perl-debug_5.44.0-1_amd64.deb
b2e68ee0be61249b82f6023cb437235ed93bdbad 8632296 perl-doc_5.44.0-1_all.deb
5e059124d30cc540a7122d5f534bf64ed7cd80ae 3264904
perl-modules-5.44_5.44.0-1_all.deb
3b41d7b0ef18f03e8282fa154a4f1dd8ee56b581 6788 perl_5.44.0-1_amd64.buildinfo
f00bc2d862927b8f02a8477412d07baec1178618 267456 perl_5.44.0-1_amd64.deb
Checksums-Sha256:
c350428472e7325f1f4c675f8b8884bc308f493bc16b01481b54cee7e23acc2b 2372
perl_5.44.0-1.dsc
82e0dcddac1dd15c4078c969628533f587a31f4e229824763cbd84ab4db628e1 422344
perl_5.44.0.orig-regen-configure.tar.xz
505cf43912e9480495c344c70260452e32aa2a73c546a026b3f100053b23ce91 14919940
perl_5.44.0.orig.tar.xz
033db6f3304e21fc74244cd8f266a4c503aa4f69550628175598bb55215c66fa 167824
perl_5.44.0-1.debian.tar.xz
42442899b17837421b14ca9c4a88f7a03469fc94ac814fe338117b20206b4a51 1169872
libperl-dev_5.44.0-1_amd64.deb
8c42c564e01a264c3c219f6a67edc4c650c6d569e099832cd2e7f8df67d40aeb 4314308
libperl5.44_5.44.0-1_amd64.deb
9e8b4cacdf5cc0b83c615a2a70e2f31d58f0b5e4cf60d84ef9ee00bc6fb16525 1893660
perl-base_5.44.0-1_amd64.deb
8fb0f5bc5fdfe6e8f1e00cf7806fe1ca9c30094c1e5aeb6e1a4d51fc69f9a47a 14229824
perl-debug_5.44.0-1_amd64.deb
629e51f6e08333f15d4db4133063cca0296d4254d4278baeacc6ee81018db18f 8632296
perl-doc_5.44.0-1_all.deb
3bb613760a3124e27812f1cb465e694c4fa16a2ab2e6e6cb995b629f2c302cbd 3264904
perl-modules-5.44_5.44.0-1_all.deb
33c02cc931ec81e38d826cfd5563f281d6effae48894e3c1c0c3a397e426a6e2 6788
perl_5.44.0-1_amd64.buildinfo
de083313f83e1f0a91dd3b2d0eacb300736fa57da075be75d06e05b3f77dff9a 267456
perl_5.44.0-1_amd64.deb
Files:
b74f725330b7a8c1022d5a0a094b50ba 2372 perl standard perl_5.44.0-1.dsc
dad7233fa6f18a19cb9a9afb90e4f4ad 422344 perl standard
perl_5.44.0.orig-regen-configure.tar.xz
55761cf1543af326492fd194647796d1 14919940 perl standard perl_5.44.0.orig.tar.xz
aa94d0156a03a38a1f064018f2fb5767 167824 perl standard
perl_5.44.0-1.debian.tar.xz
802b65b732c978e6c2a94893e0e23632 1169872 libdevel optional
libperl-dev_5.44.0-1_amd64.deb
9283ba15150c8e920f382d55278dcad0 4314308 libs optional
libperl5.44_5.44.0-1_amd64.deb
b738fa4f8077293033032235bd281a7c 1893660 perl required
perl-base_5.44.0-1_amd64.deb
a01ea1c2408ee889bd2dde7e417555ba 14229824 devel optional
perl-debug_5.44.0-1_amd64.deb
c94b049c24d91106a4202e4afa646d8b 8632296 doc optional perl-doc_5.44.0-1_all.deb
c31d62cfa1c2ccbde8639ba340673dc3 3264904 libs optional
perl-modules-5.44_5.44.0-1_all.deb
c12a01537609245f9e00c3d2af30779d 6788 perl standard
perl_5.44.0-1_amd64.buildinfo
cd0ad89ed14646911c8a9225251a9cc8 267456 perl standard perl_5.44.0-1_amd64.deb
-----BEGIN PGP SIGNATURE-----
iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCam4S8xEcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5skM0AYDaZL3Z9ilbu6MeQXc46svSz/aTZA1kz7aT
CQClJPQ80M311fKlz++6StNrHFHZMtUBegPC6+lzUsn6NzPb10c9KyfPU4Y6iypz
sDjehkY+t0ddeZURsMw7dhEww8f2dZbcSQ==
=AZ4Z
-----END PGP SIGNATURE-----
pgpRmI5hk4BIm.pgp
Description: PGP signature
--- End Message ---