Your message dated Mon, 03 Aug 2026 18:00:19 +0000
with message-id <[email protected]>
and subject line Bug#1142037: fixed in perl 5.44.0-1
has caused the Debian Bug report #1142037,
regarding perl: CVE-2026-13221
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142037: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142037
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: perl
Version: 5.40.1-8
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for perl.

CVE-2026-13221[0]:
| Perl versions through 5.43.9 produce silently incorrect regular
| expression matches when an alternation of more than 65535 fixed
| string branches is compiled into a trie in Perl_study_chunk.  When
| such branches are combined into a trie, the delta between the first
| branch and the shared tail is stored in a 16-bit field. A branch
| count above 65535 overflows the field, and the trie's match decision
| table is truncated with no warning or error.  A pattern of this
| shape produces false positive matches (matching strings it should
| not) and false negative matches (failing to match strings it
| should). When such a pattern gates an access or filtering decision,
| the result is wrong.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-13221
    https://www.cve.org/CVERecord?id=CVE-2026-13221
[1] https://lists.security.metacpan.org/cve-announce/msg/41780104/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: perl
Source-Version: 5.44.0-1
Done: Niko Tyni <[email protected]>

We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Niko Tyni <[email protected]> (supplier of updated perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA384

Format: 1.8
Date: Sat, 01 Aug 2026 16:13:58 +0300
Binary: libperl5.44 libperl-dev perl perl-base perl-debug perl-doc 
perl-modules-5.44
Source: perl
Architecture: all amd64 source
Version: 5.44.0-1
Distribution: experimental
Urgency: medium
Maintainer: Niko Tyni <[email protected]>
Changed-By: Niko Tyni <[email protected]>
Closes: 1138859 1138860 1138861 1140152 1141639 1142037
Description: 
 libperl5.44 - shared Perl library
 libperl-dev - Perl library: development files
 perl-base  - minimal Perl system
 perl-debug - debug-enabled Perl interpreter
 perl-doc   - Perl documentation
 perl       - Larry Wall's Practical Extraction and Report Language
 perl-modules-5.44 - Core Perl modules
Changes:
 perl (5.44.0-1) experimental; urgency=medium
 .
   * Update to new upstream version 5.44.0.
   * [SECURITY] includes various upstream fixes:
     + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.
         (Closes: #1141639)
     + CVE-2026-42496: Archive::Tar symlink extraction.
         (Closes: #1138860)
     + CVE-2026-42497: Archive::Tar hardlink extraction.
         (Closes: #1138859)
     + CVE-2026-9538: Archive::Tar memory exhaustion.
         (Closes: #1138861)
     + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.
         (Closes: #1140152)
     + CVE-2026-13221: silently incorrect regular expression matches.
         (Closes: #1142037)
Checksums-Sha1: 
 52da9fdc1cede54d5c3fac22d90954ac89e18eec 2372 perl_5.44.0-1.dsc
 1af3f3e6f0828e75f36ffaf50541a42a2bd33876 422344 
perl_5.44.0.orig-regen-configure.tar.xz
 f64277b1a19107491ebd59249a33b7ea986eadd4 14919940 perl_5.44.0.orig.tar.xz
 a9ae4a664ce09fba56591033c23113ef3672969b 167824 perl_5.44.0-1.debian.tar.xz
 5d0c6091ad6aa1e647e157fd0a11e02df1aedefc 1169872 libperl-dev_5.44.0-1_amd64.deb
 d5dd071615b15af9caafa6db11d10eeaab1666fc 4314308 libperl5.44_5.44.0-1_amd64.deb
 1241cdb2d398f534a9f191edc5ca3d1edeed0690 1893660 perl-base_5.44.0-1_amd64.deb
 4a8f2da10bd3820e9d67e119b6ca4a8e03694b7d 14229824 perl-debug_5.44.0-1_amd64.deb
 b2e68ee0be61249b82f6023cb437235ed93bdbad 8632296 perl-doc_5.44.0-1_all.deb
 5e059124d30cc540a7122d5f534bf64ed7cd80ae 3264904 
perl-modules-5.44_5.44.0-1_all.deb
 3b41d7b0ef18f03e8282fa154a4f1dd8ee56b581 6788 perl_5.44.0-1_amd64.buildinfo
 f00bc2d862927b8f02a8477412d07baec1178618 267456 perl_5.44.0-1_amd64.deb
Checksums-Sha256: 
 c350428472e7325f1f4c675f8b8884bc308f493bc16b01481b54cee7e23acc2b 2372 
perl_5.44.0-1.dsc
 82e0dcddac1dd15c4078c969628533f587a31f4e229824763cbd84ab4db628e1 422344 
perl_5.44.0.orig-regen-configure.tar.xz
 505cf43912e9480495c344c70260452e32aa2a73c546a026b3f100053b23ce91 14919940 
perl_5.44.0.orig.tar.xz
 033db6f3304e21fc74244cd8f266a4c503aa4f69550628175598bb55215c66fa 167824 
perl_5.44.0-1.debian.tar.xz
 42442899b17837421b14ca9c4a88f7a03469fc94ac814fe338117b20206b4a51 1169872 
libperl-dev_5.44.0-1_amd64.deb
 8c42c564e01a264c3c219f6a67edc4c650c6d569e099832cd2e7f8df67d40aeb 4314308 
libperl5.44_5.44.0-1_amd64.deb
 9e8b4cacdf5cc0b83c615a2a70e2f31d58f0b5e4cf60d84ef9ee00bc6fb16525 1893660 
perl-base_5.44.0-1_amd64.deb
 8fb0f5bc5fdfe6e8f1e00cf7806fe1ca9c30094c1e5aeb6e1a4d51fc69f9a47a 14229824 
perl-debug_5.44.0-1_amd64.deb
 629e51f6e08333f15d4db4133063cca0296d4254d4278baeacc6ee81018db18f 8632296 
perl-doc_5.44.0-1_all.deb
 3bb613760a3124e27812f1cb465e694c4fa16a2ab2e6e6cb995b629f2c302cbd 3264904 
perl-modules-5.44_5.44.0-1_all.deb
 33c02cc931ec81e38d826cfd5563f281d6effae48894e3c1c0c3a397e426a6e2 6788 
perl_5.44.0-1_amd64.buildinfo
 de083313f83e1f0a91dd3b2d0eacb300736fa57da075be75d06e05b3f77dff9a 267456 
perl_5.44.0-1_amd64.deb
Files: 
 b74f725330b7a8c1022d5a0a094b50ba 2372 perl standard perl_5.44.0-1.dsc
 dad7233fa6f18a19cb9a9afb90e4f4ad 422344 perl standard 
perl_5.44.0.orig-regen-configure.tar.xz
 55761cf1543af326492fd194647796d1 14919940 perl standard perl_5.44.0.orig.tar.xz
 aa94d0156a03a38a1f064018f2fb5767 167824 perl standard 
perl_5.44.0-1.debian.tar.xz
 802b65b732c978e6c2a94893e0e23632 1169872 libdevel optional 
libperl-dev_5.44.0-1_amd64.deb
 9283ba15150c8e920f382d55278dcad0 4314308 libs optional 
libperl5.44_5.44.0-1_amd64.deb
 b738fa4f8077293033032235bd281a7c 1893660 perl required 
perl-base_5.44.0-1_amd64.deb
 a01ea1c2408ee889bd2dde7e417555ba 14229824 devel optional 
perl-debug_5.44.0-1_amd64.deb
 c94b049c24d91106a4202e4afa646d8b 8632296 doc optional perl-doc_5.44.0-1_all.deb
 c31d62cfa1c2ccbde8639ba340673dc3 3264904 libs optional 
perl-modules-5.44_5.44.0-1_all.deb
 c12a01537609245f9e00c3d2af30779d 6788 perl standard 
perl_5.44.0-1_amd64.buildinfo
 cd0ad89ed14646911c8a9225251a9cc8 267456 perl standard perl_5.44.0-1_amd64.deb

-----BEGIN PGP SIGNATURE-----

iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCam4S8xEcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5skM0AYDaZL3Z9ilbu6MeQXc46svSz/aTZA1kz7aT
CQClJPQ80M311fKlz++6StNrHFHZMtUBegPC6+lzUsn6NzPb10c9KyfPU4Y6iypz
sDjehkY+t0ddeZURsMw7dhEww8f2dZbcSQ==
=AZ4Z
-----END PGP SIGNATURE-----

Attachment: pgpRmI5hk4BIm.pgp
Description: PGP signature


--- End Message ---

Reply via email to