Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:libnet-cidr-set-perl
User: [email protected]
Usertags: pu

[ Reason ]
This fixes CVE-2026-19566, a minor input sanitizing fix.  It's a
followup to CVE-2026-49942, which was not complete.

[ Impact ]
Depending on the usage of the library this may be a security issue.

[ Tests ]
salsa-ci passed execpt test-uscan (which isn't a problem for a
trixie-pu).  See
https://salsa.debian.org/perl-team/modules/packages/libnet-cidr-set-perl/-/pipelines/1177382
The patches ships its own test cases, which succeed.

[ Risks ]
Hopefully none...

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
Minimal fix for CVE-2026-19566 including a new test case.

[ Other info ]
According to
https://security-tracker.debian.org/tracker/CVE-2026-19566 this is a
minor issue, so it's not for DSA but for a point release.

Greetings
Roland
diff -Nru libnet-cidr-set-perl-0.15/debian/changelog libnet-cidr-set-perl-0.15/debian/changelog
--- libnet-cidr-set-perl-0.15/debian/changelog	2026-06-14 16:13:20.000000000 +0200
+++ libnet-cidr-set-perl-0.15/debian/changelog	2026-09-26 12:22:25.000000000 +0200
@@ -1,3 +1,10 @@
+libnet-cidr-set-perl (0.15-1+deb13u2) trixie; urgency=medium
+
+  * CVE-2026-19566.patch: Fix an unbounded IPv6 netmask prefix length
+    (Fixes CVE-2026-19566).
+
+ -- Roland Rosenfeld <[email protected]>  Sat, 26 Sep 2026 12:22:25 +0200
+
 libnet-cidr-set-perl (0.15-1+deb13u1) trixie; urgency=medium
 
   * CVE-2026-49940+49942.patch: Only accept ASCII digits for netmasks and
diff -Nru libnet-cidr-set-perl-0.15/debian/patches/CVE-2026-19566.patch libnet-cidr-set-perl-0.15/debian/patches/CVE-2026-19566.patch
--- libnet-cidr-set-perl-0.15/debian/patches/CVE-2026-19566.patch	1970-01-01 01:00:00.000000000 +0100
+++ libnet-cidr-set-perl-0.15/debian/patches/CVE-2026-19566.patch	2026-09-26 12:22:25.000000000 +0200
@@ -0,0 +1,29 @@
+From: Robert Rothenberg <[email protected]>
+Date: Tue, 11 Aug 2026 19:56:56 +0100
+Origin: upstream, https://github.com/robrwo/perl-Net-CIDR-Set/commit/e16b27d
+Forwarded: not-needed
+Subject: Net::CIDR::Set — bound the IPv6 netmask to in _encode
+ (The fix for CVE-2026-49942 was not complete).
+ CVE-2026-19566
+
+--- a/lib/Net/CIDR/Set/IPv6.pm
++++ b/lib/Net/CIDR/Set/IPv6.pm
+@@ -93,6 +93,7 @@ sub _encode {
+   my ( $self, $ip ) = @_;
+   if ( $ip =~ m{\A([0-9A-Fa-f:]+)/(0|[1-9][0-9]*)\z} ) {
+     my $mask = $2;
++    return if $mask > 128;
+     return unless my $addr = _pack( $1 );
+     return unless my $bits = _width2bits( $mask, 128 );
+     return ( $addr & $bits, Net::CIDR::Set::_inc( $addr | ~$bits ) );
+--- a/t/validation.t
++++ b/t/validation.t
+@@ -34,5 +34,8 @@ throws_ok {
+     Net::CIDR::Set->new->add("::1/02");
+ } qr{^Can't decode ::1/02 as an IPv4 or IPv6 address};
+ 
++throws_ok {
++    Net::CIDR::Set->new->add("2001:db8::/129");
++} qr{^Can't decode 2001:db8::/129 as an IPv4 or IPv6 addres};
+ 
+ done_testing;
diff -Nru libnet-cidr-set-perl-0.15/debian/patches/series libnet-cidr-set-perl-0.15/debian/patches/series
--- libnet-cidr-set-perl-0.15/debian/patches/series	2026-06-14 16:13:20.000000000 +0200
+++ libnet-cidr-set-perl-0.15/debian/patches/series	2026-09-26 12:22:25.000000000 +0200
@@ -1,2 +1,3 @@
 CVE-2026-49940+49942.patch
 CVE-2026-49941.patch
+CVE-2026-19566.patch

Attachment: signature.asc
Description: PGP signature

Reply via email to