[CLSA-2026:1786471358] Fix CVE(s): CVE-2026-42496, CVE-2026-48962
Type:
security
Severity:
Critical
Release date:
2026-08-11 18:02:48 UTC
Description:
* SECURITY UPDATE: Archive::Tar extracted symlinks and hardlinks with attacker-controlled targets outside the extraction directory - debian/patches/fixes/CVE-2026-42496.patch: reject absolute and '..'-traversing link targets in Archive::Tar::_make_special_file() unless $Archive::Tar::INSECURE_EXTRACT_MODE is set - CVE-2026-42496 * SECURITY UPDATE: arbitrary code execution in File::GlobMapper via an attacker-controlled output glob - debian/patches/fixes/CVE-2026-48962.patch: replace the eval STRING in File::GlobMapper::_getFiles() with explicit substitution of internal wildcard markers, so no part of the output glob is evaluated as Perl - CVE-2026-48962
Updated packages:
  • libperl-dev_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
    sha:a8bd684b2a0af46f791d2b902014bdaa92e30347
  • libperl5.28_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
    sha:d92800f7d04dc0f59116e618c29bd49e6e1557fd
  • perl_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
    sha:125891dfc7c7c0e733c71d658c5c7030001c3860
  • perl-base_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
    sha:54c6604fb6801dc0c19e8730c8ea31384a6b1cea
  • perl-debug_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
    sha:ba1767963e28c5eea20710a299e866abed4ffe45
  • perl-doc_5.28.1-6+deb10u1+tuxcare.els5_all.deb
    sha:1f569c824680ba8fcee1b9bca8d76e05358ee8de
  • perl-modules-5.28_5.28.1-6+deb10u1+tuxcare.els5_all.deb
    sha:426cd7b599f65503f2d573d5167d407ce02dd6ec
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.