Your message dated Sun, 16 Aug 2026 14:00:05 +0200
with message-id <[email protected]>
and subject line Re: Bug#1144498: perl: 8 unpatched security CVEs - request fix
for trixie
has caused the Debian Bug report #1144498,
regarding perl: 8 unpatched security CVEs - request fix for trixie
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144498: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144498
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: perl
Version: 5.40.1-6
Severity: Critical & High
Hi Debian Security Team,
The following CVEs are reported against the perl source package in Trixie and
have no fix available at time of filing.
S.No
CVE
CVSS
Component
Issue
1
CVE-2026-57433
9.8
Storable
Signed integer overflow on SX_HOOK deserialization; crafted thaw() input panics
the process
2
CVE-2026-12087
9.1
Socket
pack_ip_mreq_source() validates wrong argument length; heap out-of-bounds read
up to 3 bytes
3
CVE-2026-13221
9.1
perl core (regex)
Alternation > 65535 branches overflows 16-bit trie field; silent
false-positive/negative matches
4
CVE-2026-57432
8.4
perl core (pack/un
Integer overflow in S_measure_struct; large repeat count leaks heap memory to
caller
5
CVE-2026-48959
7.5
IO::Uncompress
fastForward() compares offset digit count instead of offset value; CPU
exhaustion on crafted zip
6
CVE-2026-48962
7.3
IO::Compress
File::GlobMapper runs caller-supplied output glob through eval STRING;
arbitrary code execution
7
CVE-2026-48961
7.3
IO::Compress
zipdetails crashes on Info-ZIP Unix Extra Field with 8-byte UID/GID; undefined
subroutine
8
CVE-2026-7017
7.1
HTTP::Tiny
Authorization/Cookie headers forwarded to cross-origin redirect targets without
origin check
All eight CVEs show Fix Status: open on the Debian security tracker. Please
provide patched packages for trixie.
Regards,
Ejas Ali
________________________________
This message is for the designated recipient only and may contain privileged,
proprietary, or otherwise confidential information. If you have received it in
error, please notify the sender immediately and delete the original. Any other
use of the e-mail by you is prohibited. Where allowed by local law, electronic
communications with Accenture and its affiliates, including e-mail and instant
messaging (including content), may be scanned by our systems for the purposes
of information security, AI-powered support capabilities, and assessment of
internal compliance with Accenture policy. Your privacy is important to us.
Accenture uses your personal data only in compliance with data protection laws.
For further information on how Accenture processes your personal data, please
see our privacy statement at https://www.accenture.com/us-en/privacy-policy.
______________________________________________________________________________________
www.accenture.com
--- End Message ---
--- Begin Message ---
On Sun, Aug 16, 2026 at 07:33:45AM +0000, Mohammad, Ejas Ali wrote:
> Package: perl
> Version: 5.40.1-6
> Severity: Critical & High
>
> Hi Debian Security Team,
>
> The following CVEs are reported against the perl source package in Trixie and
> have no fix available at time of filing.
There are already bugs filed for these CVEs, and as you say they are
tracked in the security tracker.
There is no need for an additional bug to keep track of the work. Closing this
one.
I assume this was not an offer of a tested package that is ready for
trixie-security?
Best,
Chris
--- End Message ---