Release date:
2026-08-11 18:02:48 UTC
Description:
* SECURITY UPDATE: Archive::Tar extracted symlinks and hardlinks with
attacker-controlled targets outside the extraction directory
- debian/patches/fixes/CVE-2026-42496.patch: reject absolute and
'..'-traversing link targets in Archive::Tar::_make_special_file()
unless $Archive::Tar::INSECURE_EXTRACT_MODE is set
- CVE-2026-42496
* SECURITY UPDATE: arbitrary code execution in File::GlobMapper via an
attacker-controlled output glob
- debian/patches/fixes/CVE-2026-48962.patch: replace the eval STRING in
File::GlobMapper::_getFiles() with explicit substitution of internal
wildcard markers, so no part of the output glob is evaluated as Perl
- CVE-2026-48962
Updated packages:
-
libperl-dev_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
sha:a8bd684b2a0af46f791d2b902014bdaa92e30347
-
libperl5.28_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
sha:d92800f7d04dc0f59116e618c29bd49e6e1557fd
-
perl_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
sha:125891dfc7c7c0e733c71d658c5c7030001c3860
-
perl-base_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
sha:54c6604fb6801dc0c19e8730c8ea31384a6b1cea
-
perl-debug_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb
sha:ba1767963e28c5eea20710a299e866abed4ffe45
-
perl-doc_5.28.1-6+deb10u1+tuxcare.els5_all.deb
sha:1f569c824680ba8fcee1b9bca8d76e05358ee8de
-
perl-modules-5.28_5.28.1-6+deb10u1+tuxcare.els5_all.deb
sha:426cd7b599f65503f2d573d5167d407ce02dd6ec
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.