Package: release.debian.org Severity: normal Tags: trixie X-Debbugs-Cc: [email protected] Control: affects -1 + src:libnet-cidr-set-perl User: [email protected] Usertags: pu
[ Reason ] This fixes CVE-2026-19566, a minor input sanitizing fix. It's a followup to CVE-2026-49942, which was not complete. [ Impact ] Depending on the usage of the library this may be a security issue. [ Tests ] salsa-ci passed execpt test-uscan (which isn't a problem for a trixie-pu). See https://salsa.debian.org/perl-team/modules/packages/libnet-cidr-set-perl/-/pipelines/1177382 The patches ships its own test cases, which succeed. [ Risks ] Hopefully none... [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in stable [x] the issue is verified as fixed in unstable [ Changes ] Minimal fix for CVE-2026-19566 including a new test case. [ Other info ] According to https://security-tracker.debian.org/tracker/CVE-2026-19566 this is a minor issue, so it's not for DSA but for a point release. Greetings Roland
diff -Nru libnet-cidr-set-perl-0.15/debian/changelog libnet-cidr-set-perl-0.15/debian/changelog --- libnet-cidr-set-perl-0.15/debian/changelog 2026-06-14 16:13:20.000000000 +0200 +++ libnet-cidr-set-perl-0.15/debian/changelog 2026-09-26 12:22:25.000000000 +0200 @@ -1,3 +1,10 @@ +libnet-cidr-set-perl (0.15-1+deb13u2) trixie; urgency=medium + + * CVE-2026-19566.patch: Fix an unbounded IPv6 netmask prefix length + (Fixes CVE-2026-19566). + + -- Roland Rosenfeld <[email protected]> Sat, 26 Sep 2026 12:22:25 +0200 + libnet-cidr-set-perl (0.15-1+deb13u1) trixie; urgency=medium * CVE-2026-49940+49942.patch: Only accept ASCII digits for netmasks and diff -Nru libnet-cidr-set-perl-0.15/debian/patches/CVE-2026-19566.patch libnet-cidr-set-perl-0.15/debian/patches/CVE-2026-19566.patch --- libnet-cidr-set-perl-0.15/debian/patches/CVE-2026-19566.patch 1970-01-01 01:00:00.000000000 +0100 +++ libnet-cidr-set-perl-0.15/debian/patches/CVE-2026-19566.patch 2026-09-26 12:22:25.000000000 +0200 @@ -0,0 +1,29 @@ +From: Robert Rothenberg <[email protected]> +Date: Tue, 11 Aug 2026 19:56:56 +0100 +Origin: upstream, https://github.com/robrwo/perl-Net-CIDR-Set/commit/e16b27d +Forwarded: not-needed +Subject: Net::CIDR::Set — bound the IPv6 netmask to in _encode + (The fix for CVE-2026-49942 was not complete). + CVE-2026-19566 + +--- a/lib/Net/CIDR/Set/IPv6.pm ++++ b/lib/Net/CIDR/Set/IPv6.pm +@@ -93,6 +93,7 @@ sub _encode { + my ( $self, $ip ) = @_; + if ( $ip =~ m{\A([0-9A-Fa-f:]+)/(0|[1-9][0-9]*)\z} ) { + my $mask = $2; ++ return if $mask > 128; + return unless my $addr = _pack( $1 ); + return unless my $bits = _width2bits( $mask, 128 ); + return ( $addr & $bits, Net::CIDR::Set::_inc( $addr | ~$bits ) ); +--- a/t/validation.t ++++ b/t/validation.t +@@ -34,5 +34,8 @@ throws_ok { + Net::CIDR::Set->new->add("::1/02"); + } qr{^Can't decode ::1/02 as an IPv4 or IPv6 address}; + ++throws_ok { ++ Net::CIDR::Set->new->add("2001:db8::/129"); ++} qr{^Can't decode 2001:db8::/129 as an IPv4 or IPv6 addres}; + + done_testing; diff -Nru libnet-cidr-set-perl-0.15/debian/patches/series libnet-cidr-set-perl-0.15/debian/patches/series --- libnet-cidr-set-perl-0.15/debian/patches/series 2026-06-14 16:13:20.000000000 +0200 +++ libnet-cidr-set-perl-0.15/debian/patches/series 2026-09-26 12:22:25.000000000 +0200 @@ -1,2 +1,3 @@ CVE-2026-49940+49942.patch CVE-2026-49941.patch +CVE-2026-19566.patch
signature.asc
Description: PGP signature

