Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Ubuntu 25.10 Perl Critical Denial of Service Fix USN-8467-2

Дата публикации: 03-07-2026 12:33:04

Several security issues were fixed in Perl.

Основное содержимое страницы с новостью.

Several security issues were fixed in Perl.

Summary

Several security issues were fixed in Perl.

Software Description:

- perl: Practical Extraction and Report Language

Details:

USN-8467-1 fixed vulnerabilities in Perl. This update provides the

corresponding fix for Perl on Ubuntu 25.10.

Original advisory details:

It was discovered that Perl's Archive::Tar module incorrectly handled

symlink and hardlink targets during extraction. An attacker could use this

issue to read or overwrite arbitrary files outside the extraction

directory. (CVE-2026-42496)

It was discovered that Perl had a heap buffer overflow when compiling

regular expressions with a repeated fixed string on 32-bit builds. An

attacker could use this issue to cause a denial of service or possibly

execute arbitrary code. (CVE-2026-8376)

Topics%20covered

Topics Covered
Update Instructions
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  libperl-dev                     5.40.1-6ubuntu0.1
  libperl5.40                     5.40.1-6ubuntu0.1
  perl                            5.40.1-6ubuntu0.1
  perl-base                       5.40.1-6ubuntu0.1
  perl-debug                      5.40.1-6ubuntu0.1
  perl-modules-5.40               5.40.1-6ubuntu0.1

In general, a standard system update will make all the necessary changes.
References

https://ubuntu.com/security/notices/USN-8467-2

https://ubuntu.com/security/notices/USN-8467-1

CVE-2026-42496, CVE-2026-8376

Package Information
Related Articles

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1SUSE CUPS Moderate Denial of Service Issues Fixed 2026-2732-10503-07-2026
2SUSE 15 SP6 Buildah Important Denial Of Service Issues SUSE-SU-2026-2733-10503-07-2026
3Rocky Linux ruby Important Command Injection Threat RLSA-2026-335140530-06-2026
4SUSE 2026-2731-1 editorconfig-core-c Moderate Stack Overflow Threat0503-07-2026
5Rocky Linux perl Important Security Update RLSA-2026-30851 CVE-2026-424960529-06-2026
6Rocky Linux 8 Autotrace Moderate Buffer Overflow Fix RLSA-2023-30670528-06-2026
7Rocky Linux 8 RLSA-2026-32992 Python3.12 Urllib3 Important DoS Issue0501-07-2026
8Rocky Linux Container-Tools Significant Security Advisory RLSA-2026-337220501-07-2026
9Rocky Linux 8 glibc Moderate Heap Buffer Overflow Update RLSA-2026-331260501-07-2026
10Rocky Linux RLSA-2026-33515 Ruby Important Denial of Service Threats0530-06-2026

Классификация: Общество. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 5. Источник: www.linuxsecurity.com.