Opened 3 weeks ago

Closed 9 days ago

#5976 closed enhancement (overcomebyevents)

perl CVE-2026-13221 and 57432

Reported by: Joe Locash Owned by: lfs-book
Priority: normal Milestone: 13.1
Component: Book Version: git
Severity: normal Keywords:
Cc:

Description

Just reporting for those interested.

Message-Id: <E4CFC743-A21C-448F-8141-5E9FF5E1F22B@stig.io>
Date: Mon, 13 Jul 2026 17:43:01 +0200
From: Stig Palmquist <stig@...g.io>
To: cve-announce@...urity.metacpan.org,
 oss-security@...ts.openwall.com
Subject: CVE-2026-13221: Perl versions through 5.43.9 produce silently
 incorrect regular expression matches when an alternation of more than 65535
 fixed string branches is compiled into a trie in Perl_study_chunk

========================================================================
CVE-2026-13221                                       CPAN Security Group
========================================================================

        CVE ID:  CVE-2026-13221
  Distribution:  perl
      Versions:  through 5.43.9

      MetaCPAN:  https://metacpan.org/dist/perl
      VCS Repo:  https://github.com/Perl/perl5


Perl versions through 5.43.9 produce silently incorrect regular
expression matches when an alternation of more than 65535 fixed string
branches is compiled into a trie in Perl_study_chunk

Description
-----------
Perl versions through 5.43.9 produce silently incorrect regular
expression matches when an alternation of more than 65535 fixed string
branches is compiled into a trie in Perl_study_chunk.

When such branches are combined into a trie, the delta between the
first branch and the shared tail is stored in a 16-bit field. A branch
count above 65535 overflows the field, and the trie's match decision
table is truncated with no warning or error.

A pattern of this shape produces false positive matches (matching
strings it should not) and false negative matches (failing to match
strings it should). When such a pattern gates an access or filtering
decision, the result is wrong.

Problem types
-------------
- CWE-190 Integer Overflow or Wraparound

Solutions
---------
Apply the upstream patch. The fix is included in the Perl 5.43.10
development release.


References
----------
https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch
https://github.com/Perl/perl5/issues/23388
Message-Id: <4707DBC6-795C-4A34-92C3-01733583170F@stig.io>
Date: Mon, 13 Jul 2026 17:45:47 +0200
From: Stig Palmquist <stig@...g.io>
To: cve-announce@...urity.metacpan.org,
 oss-security@...ts.openwall.com
Subject: CVE-2026-57432: Perl versions through 5.43.10 have an integer
 overflow in S_measure_struct leading to an out-of-bounds heap read in pack
 and unpack

========================================================================
CVE-2026-57432                                       CPAN Security Group
========================================================================

        CVE ID:  CVE-2026-57432
  Distribution:  perl
      Versions:  through 5.43.10

      MetaCPAN:  https://metacpan.org/dist/perl
      VCS Repo:  https://github.com/Perl/perl5


Perl versions through 5.43.10 have an integer overflow in
S_measure_struct leading to an out-of-bounds heap read in pack and
unpack

Description
-----------
Perl versions through 5.43.10 have an integer overflow in
S_measure_struct leading to an out-of-bounds heap read in pack and
unpack.

S_measure_struct adds each item's size times its repeat count to a
running total with no overflow check, so a large repeat count in a pack
or unpack template wraps the signed SSize_t total negative. The @, X,
and x position codes then guard their moves with a signed length
comparison that passes when the length is negative, advancing the
buffer pointer out of bounds.

A template derived from untrusted input can read heap memory past the
buffer and return it to the caller.

Problem types
-------------
- CWE-190 Integer Overflow or Wraparound
- CWE-125 Out-of-bounds Read

Solutions
---------
Apply the upstream patches. The fix is included in the Perl 5.43.11
development release.


References
----------
https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch
https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch

Change History (2)

comment:1 by Bruce Dubbs, 3 weeks ago

As best I can tell perl-5,44 is due to be released any time now, I'm going to hold off on this ticket for now, but will apply the patches if there is no release before the package freeze for LFS-13.1 in August 15.

comment:2 by Xi Ruoyao, 9 days ago

Resolution: overcomebyevents
Status: newclosed

Update to 5.44.0 per #5980 will fix them.

Note: See TracTickets for help on using tickets.