[CLSA-2026:1784303555] Fix CVE(s): CVE-2026-13221, CVE-2026-57432
Type:
security
Severity:
Critical
Release date:
2026-07-17 15:52:59 UTC
Description:
* SECURITY UPDATE: regex trie 16-bit next-offset overflow (GH#23388) - debian/patches/CVE-2026-13221.patch: do not build a trie when the branch-to-tail delta would overflow the 16-bit next-offset field in S_study_chunk() in regcomp.c - CVE-2026-13221 * SECURITY UPDATE: integer overflow in pack/unpack structure sizing (S_measure_struct); a large repeat count wraps the signed size negative, leading to an out-of-bounds heap read - debian/patches/CVE-2026-57432.patch: integer overflow in pack/unpack structure sizing (S_measure_struct); a large repeat count wraps the signed size negative, leading to an out-of-bounds heap read - CVE-2026-57432
Updated packages:
  • libperl-dev_5.26.1-6ubuntu0.7+tuxcare.els3_amd64.deb
    sha:7c9d339328a976daa1653a75c1f792161a6ee3e7
  • libperl5.26_5.26.1-6ubuntu0.7+tuxcare.els3_amd64.deb
    sha:7802a6b320dc2b5dd50eb56f7281b2ea8a28fc81
  • perl_5.26.1-6ubuntu0.7+tuxcare.els3_amd64.deb
    sha:47daf13df3449c09c1b0de25585ff1cf619f20d1
  • perl-base_5.26.1-6ubuntu0.7+tuxcare.els3_amd64.deb
    sha:7872636f6305814559ee15bd3697a6645fd92686
  • perl-debug_5.26.1-6ubuntu0.7+tuxcare.els3_amd64.deb
    sha:8b62d51aa5770bc757895bf1d6fcc0412d43ca12
  • perl-doc_5.26.1-6ubuntu0.7+tuxcare.els3_all.deb
    sha:62f5bb92fae94ce81a69194b74bb515d5fdb16b0
  • perl-modules-5.26_5.26.1-6ubuntu0.7+tuxcare.els3_all.deb
    sha:afa0cde4cbde8c5831af788880384913ff82131e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.