Opened 3 weeks ago
Closed 9 days ago
#5976 closed enhancement (overcomebyevents)
perl CVE-2026-13221 and 57432
| Reported by: | Joe Locash | Owned by: | lfs-book |
|---|---|---|---|
| Priority: | normal | Milestone: | 13.1 |
| Component: | Book | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
Just reporting for those interested.
Message-Id: <E4CFC743-A21C-448F-8141-5E9FF5E1F22B@stig.io>
Date: Mon, 13 Jul 2026 17:43:01 +0200
From: Stig Palmquist <stig@...g.io>
To: cve-announce@...urity.metacpan.org,
oss-security@...ts.openwall.com
Subject: CVE-2026-13221: Perl versions through 5.43.9 produce silently
incorrect regular expression matches when an alternation of more than 65535
fixed string branches is compiled into a trie in Perl_study_chunk
========================================================================
CVE-2026-13221 CPAN Security Group
========================================================================
CVE ID: CVE-2026-13221
Distribution: perl
Versions: through 5.43.9
MetaCPAN: https://metacpan.org/dist/perl
VCS Repo: https://github.com/Perl/perl5
Perl versions through 5.43.9 produce silently incorrect regular
expression matches when an alternation of more than 65535 fixed string
branches is compiled into a trie in Perl_study_chunk
Description
-----------
Perl versions through 5.43.9 produce silently incorrect regular
expression matches when an alternation of more than 65535 fixed string
branches is compiled into a trie in Perl_study_chunk.
When such branches are combined into a trie, the delta between the
first branch and the shared tail is stored in a 16-bit field. A branch
count above 65535 overflows the field, and the trie's match decision
table is truncated with no warning or error.
A pattern of this shape produces false positive matches (matching
strings it should not) and false negative matches (failing to match
strings it should). When such a pattern gates an access or filtering
decision, the result is wrong.
Problem types
-------------
- CWE-190 Integer Overflow or Wraparound
Solutions
---------
Apply the upstream patch. The fix is included in the Perl 5.43.10
development release.
References
----------
https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch
https://github.com/Perl/perl5/issues/23388
Message-Id: <4707DBC6-795C-4A34-92C3-01733583170F@stig.io>
Date: Mon, 13 Jul 2026 17:45:47 +0200
From: Stig Palmquist <stig@...g.io>
To: cve-announce@...urity.metacpan.org,
oss-security@...ts.openwall.com
Subject: CVE-2026-57432: Perl versions through 5.43.10 have an integer
overflow in S_measure_struct leading to an out-of-bounds heap read in pack
and unpack
========================================================================
CVE-2026-57432 CPAN Security Group
========================================================================
CVE ID: CVE-2026-57432
Distribution: perl
Versions: through 5.43.10
MetaCPAN: https://metacpan.org/dist/perl
VCS Repo: https://github.com/Perl/perl5
Perl versions through 5.43.10 have an integer overflow in
S_measure_struct leading to an out-of-bounds heap read in pack and
unpack
Description
-----------
Perl versions through 5.43.10 have an integer overflow in
S_measure_struct leading to an out-of-bounds heap read in pack and
unpack.
S_measure_struct adds each item's size times its repeat count to a
running total with no overflow check, so a large repeat count in a pack
or unpack template wraps the signed SSize_t total negative. The @, X,
and x position codes then guard their moves with a signed length
comparison that passes when the length is negative, advancing the
buffer pointer out of bounds.
A template derived from untrusted input can read heap memory past the
buffer and return it to the caller.
Problem types
-------------
- CWE-190 Integer Overflow or Wraparound
- CWE-125 Out-of-bounds Read
Solutions
---------
Apply the upstream patches. The fix is included in the Perl 5.43.11
development release.
References
----------
https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch
https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch
Change History (2)
comment:1 by , 3 weeks ago
comment:2 by , 9 days ago
| Resolution: | → overcomebyevents |
|---|---|
| Status: | new → closed |
Update to 5.44.0 per #5980 will fix them.
Note:
See TracTickets
for help on using tickets.

As best I can tell perl-5,44 is due to be released any time now, I'm going to hold off on this ticket for now, but will apply the patches if there is no release before the package freeze for LFS-13.1 in August 15.