Source: perl Version: 5.42.2-3 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for perl. Filling a bug for tracking the issue. CVE-2026-15534[0]: | Perl versions through 5.45.1 have out-of-bounds heap reads and | writes during regular expression matching via an undersized | superlinear cache in S_regmatch. The regex engine's superlinear | cache holds one bit per subject position for each participating | WHILEM node, so the bit count is the subject length plus one times | the number of nodes. Nothing checks that product for positive | overflow of the signed 32-bit count: a 286331153 byte subject | matched against a pattern with 15 participating nodes stores the | count as 14, leaving a two byte cache. The cache is then indexed | from the real match position and node number, so reads go past the | end of the allocation, and on failure CACHEsayNO sets a bit past it. | A caller that matches an attacker controlled subject of this size | against a pattern of this shape can crash the process or corrupt | heap memory. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15534 https://www.cve.org/CVERecord?id=CVE-2026-15534 [1] https://lists.security.metacpan.org/cve-announce/msg/42536248/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore

