Debian dla-4821 : libperl-dev - security update

critical Nessus Plugin ID 362949

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4821 advisory.

- ------------------------------------------------------------------------- Debian LTS Advisory DLA-4821-1 [email protected] https://www.debian.org/lts/security/ Arnaud Rebillout October 05, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : perl Version : 5.36.0-7+deb12u4 CVE ID : CVE-2025-15649 CVE-2026-7010 CVE-2026-7017 CVE-2026-8376 CVE-2026-12087 CVE-2026-13221 CVE-2026-19487 CVE-2026-42496 CVE-2026-42497 CVE-2026-48959 CVE-2026-48962 CVE-2026-57432 CVE-2026-57433 Debian Bug : 1137345 1138854 1138856 1138858 1138859 1138860 1138863 1138905 1138906 1140152 1141639 1142037 1144668

Multiple vulnerabilities were discovered in the Perl programming language.

CVE-2025-15649

header parsing in IO::Uncompress::Unzip

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.
_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die. The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.

CVE-2026-7010

CRLF-validation in HTTP::Tiny

HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.
An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.

CVE-2026-7017

HTTP::Tiny credential forwarding on redirects

HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that Authorization headers will not be included in a redirected request applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.

CVE-2026-8376

Buffer overflow in Perl_study_chunk

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount
* l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.

CVE-2026-12087

Socket: pack_ip_mreq_source() out-of-bounds heap read

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.

CVE-2026-13221

silently incorrect regular expression matches

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.

CVE-2026-19487

incorrect regular expression match results

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds. Example: ABCDE =~ m/ABCF|BCDE|C/; # matches C at offset 2, not BCDE ABCDE =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.

CVE-2026-42496

Archive::Tar symlink extraction

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVE-2026-42497

Archive::Tar hardlink extraction

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.
_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

CVE-2026-48959

CPU exhaustion in IO::Uncompress::Unzip

IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.

CVE-2026-48962

code execution in IO-Compress via output globs

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.
_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVE-2026-57432

out of bound heap reads in pack() and unpack()

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.
S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.

CVE-2026-57433

signed integer overflow in Storable

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

For Debian 12 bookworm, these problems have been fixed in version 5.36.0-7+deb12u4.

We recommend that you upgrade your perl packages.

For the detailed security status of perl please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/perl

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the libperl-dev packages.

See Also

https://packages.debian.org/source/bookworm/perl

https://security-tracker.debian.org/tracker/CVE-2025-15649

https://security-tracker.debian.org/tracker/CVE-2026-12087

https://security-tracker.debian.org/tracker/CVE-2026-13221

https://security-tracker.debian.org/tracker/CVE-2026-19487

https://security-tracker.debian.org/tracker/CVE-2026-42496

https://security-tracker.debian.org/tracker/CVE-2026-42497

https://security-tracker.debian.org/tracker/CVE-2026-48959

https://security-tracker.debian.org/tracker/CVE-2026-48962

https://security-tracker.debian.org/tracker/CVE-2026-57432

https://security-tracker.debian.org/tracker/CVE-2026-57433

https://security-tracker.debian.org/tracker/CVE-2026-7010

https://security-tracker.debian.org/tracker/CVE-2026-7017

https://security-tracker.debian.org/tracker/CVE-2026-8376

https://security-tracker.debian.org/tracker/source-package/perl

Plugin Details

Severity: Critical

ID: 362949

File Name: debian_DLA-4821.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/5/2026

Updated: 10/5/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.1

Percentile: 98.36

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-8376

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:libperl-dev, p-cpe:/a:debian:debian_linux:libperl5.36, p-cpe:/a:debian:debian_linux:perl-base, p-cpe:/a:debian:debian_linux:perl-debug, p-cpe:/a:debian:debian_linux:perl-doc, p-cpe:/a:debian:debian_linux:perl-modules-5.36, p-cpe:/a:debian:debian_linux:perl

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/5/2026

Vulnerability Publication Date: 5/11/2026

Reference Information

CVE: CVE-2025-15649, CVE-2026-12087, CVE-2026-13221, CVE-2026-19487, CVE-2026-42496, CVE-2026-42497, CVE-2026-48959, CVE-2026-48962, CVE-2026-57432, CVE-2026-57433, CVE-2026-7010, CVE-2026-7017, CVE-2026-8376

IAVA: 2026-A-0618, 2026-A-0696-S, 2026-A-0889