Your message dated Sun, 16 Aug 2026 14:00:05 +0200
with message-id <[email protected]>
and subject line Re: Bug#1144498: perl: 8 unpatched security CVEs - request fix 
for trixie
has caused the Debian Bug report #1144498,
regarding perl: 8 unpatched security CVEs - request fix for trixie
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144498: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144498
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: perl
Version: 5.40.1-6
Severity: Critical & High

Hi Debian Security Team,

The following CVEs are reported against the perl source package in Trixie and 
have no fix available at time of filing.

S.No
CVE
CVSS
Component
Issue
1
CVE-2026-57433
9.8
Storable
Signed integer overflow on SX_HOOK deserialization; crafted thaw() input panics 
the process
2
CVE-2026-12087
9.1
Socket
pack_ip_mreq_source() validates wrong argument length; heap out-of-bounds read 
up to 3 bytes
3
CVE-2026-13221
9.1
perl core (regex)
Alternation > 65535 branches overflows 16-bit trie field; silent 
false-positive/negative matches
4
CVE-2026-57432
8.4
perl core (pack/un
Integer overflow in S_measure_struct; large repeat count leaks heap memory to 
caller
5
CVE-2026-48959
7.5
IO::Uncompress
fastForward() compares offset digit count instead of offset value; CPU 
exhaustion on crafted zip
6
CVE-2026-48962
7.3
IO::Compress
File::GlobMapper runs caller-supplied output glob through eval STRING; 
arbitrary code execution
7
CVE-2026-48961
7.3
IO::Compress
zipdetails crashes on Info-ZIP Unix Extra Field with 8-byte UID/GID; undefined 
subroutine
8
CVE-2026-7017
7.1
HTTP::Tiny
Authorization/Cookie headers forwarded to cross-origin redirect targets without 
origin check

All eight CVEs show Fix Status: open on the Debian security tracker. Please 
provide patched packages for trixie.

Regards,
Ejas Ali


________________________________

This message is for the designated recipient only and may contain privileged, 
proprietary, or otherwise confidential information. If you have received it in 
error, please notify the sender immediately and delete the original. Any other 
use of the e-mail by you is prohibited. Where allowed by local law, electronic 
communications with Accenture and its affiliates, including e-mail and instant 
messaging (including content), may be scanned by our systems for the purposes 
of information security, AI-powered support capabilities, and assessment of 
internal compliance with Accenture policy. Your privacy is important to us. 
Accenture uses your personal data only in compliance with data protection laws. 
For further information on how Accenture processes your personal data, please 
see our privacy statement at https://www.accenture.com/us-en/privacy-policy.
______________________________________________________________________________________

www.accenture.com

--- End Message ---
--- Begin Message ---
On Sun, Aug 16, 2026 at 07:33:45AM +0000, Mohammad, Ejas Ali wrote:
> Package: perl
> Version: 5.40.1-6
> Severity: Critical & High
> 
> Hi Debian Security Team,
> 
> The following CVEs are reported against the perl source package in Trixie and 
> have no fix available at time of filing.

There are already bugs filed for these CVEs, and as you say they are 
tracked in the security tracker.

There is no need for an additional bug to keep track of the work. Closing this 
one.

I assume this was not an offer of a tested package that is ready for 
trixie-security?

Best,
Chris

--- End Message ---

Reply via email to