Echo: perl: security update to 5.40.1-6+e18

medium Tenable Cloud Security Plugin ID 464299

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale
failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for
positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A
failing transition sets the failed flag, and a later successful transition does not clear it, so the
prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier.
It takes a subject where one candidate is recorded and a later character then forces a fallback through a
fail link that succeeds. Example: "ABCDE" =~ m/ABCF|BCDE|C/; # matches C at offset 2, not BCDE "ABCDE" =~
m/ABCF|BCDE|C(G)/; # no match, BCDE missed An alternation like this can miss input it should match, or
match it on the wrong branch, so an access or filtering decision made from the result can be wrong.
(CVE-2026-19487)

Solution

Update the perl library and its related packages to version 5.40.1-6+e18 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-19487

Plugin Details

Severity: Medium

ID: 464299

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-19487

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/14/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-19487

IAVA: 2026-A-0889