Home / mailingsPDF  

[USN-8675-1] Perl vulnerabilities

Posted on 25 August 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8675-1
August 25, 2026

perl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Perl.

Software Description:
- perl: Practical Extraction and Report Language

Details:

It was discovered that Perl incorrectly handled short source addresses
in the Socket module. An attacker could possibly use this issue to
trigger an out-of-bounds heap read, resulting in information disclosure.
(CVE-2026-12087)

It was discovered that Perl incorrectly handled regular expressions
containing a large number of fixed string alternatives. An attacker
could possibly use this issue to cause incorrect regular expression
matches, resulting in security restrictions being bypassed.
(CVE-2026-13221)

It was discovered that Perl incorrectly handled certain large repeat
counts when processing pack and unpack templates. An attacker could
possibly use this issue to trigger an out-of-bounds heap read, resulting
in information disclosure. (CVE-2026-57432)

It was discovered that Perl incorrectly handled certain crafted data
when deserializing with the Storable module. An attacker could possibly
use this issue to trigger an integer overflow and application
termination, resulting in a denial of service. (CVE-2026-57433)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
libperl5.34 5.34.0-3ubuntu1.8
perl-base 5.34.0-3ubuntu1.8
perl-modules-5.34 5.34.0-3ubuntu1.8

Ubuntu 20.04 LTS
libperl5.30 5.30.0-9ubuntu0.5+esm3
Available with Ubuntu Pro
perl-base 5.30.0-9ubuntu0.5+esm3
Available with Ubuntu Pro
perl-modules-5.30 5.30.0-9ubuntu0.5+esm3
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libperl5.26 5.26.1-6ubuntu0.7+esm3
Available with Ubuntu Pro
perl-base 5.26.1-6ubuntu0.7+esm3
Available with Ubuntu Pro
perl-modules-5.26 5.26.1-6ubuntu0.7+esm3
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libperl5.22 5.22.1-9ubuntu0.9+esm3
Available with Ubuntu Pro
perl-base 5.22.1-9ubuntu0.9+esm3
Available with Ubuntu Pro
perl-modules-5.22 5.22.1-9ubuntu0.9+esm3
Available with Ubuntu Pro

Ubuntu 14.04 LTS
libperl5.18 5.18.2-2ubuntu1.7+esm8
Available with Ubuntu Pro
perl-base 5.18.2-2ubuntu1.7+esm8
Available with Ubuntu Pro
perl-modules 5.18.2-2ubuntu1.7+esm8
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8675-1
CVE-2026-12087, CVE-2026-13221, CVE-2026-57432, CVE-2026-57433

Package Information:
https://launchpad.net/ubuntu/+source/perl/5.34.0-3ubuntu1.8

--===============1722609570296912194==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP