USN-8684-1
Dashboard / Vulnerabilities / USN-8684-1
USN-8684-1
Summary: perl vulnerabilities
Details: It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered that Perl incorrectly handled regular expressions with a large number of alternation branches. An attacker could possibly use this issue to cause incorrect matching results. (CVE-2026-13221) It was discovered that Perl incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-57433, CVE-2025-15649, CVE-2026-48959, CVE-2026-9538) It was discovered that Perl incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-48962) It was discovered that Perl incorrectly handled credential headers during cross-origin redirects in HTTP::Tiny. An attacker could possibly use this issue to expose sensitive information. (CVE-2026-7017)
References: https://ubuntu.com/security/notices/USN-8684-1, https://ubuntu.com/security/CVE-2025-15649, https://ubuntu.com/security/CVE-2026-7017, https://ubuntu.com/security/CVE-2026-9538, https://ubuntu.com/security/CVE-2026-12087, https://ubuntu.com/security/CVE-2026-13221, https://ubuntu.com/security/CVE-2026-48959, https://ubuntu.com/security/CVE-2026-48962, https://ubuntu.com/security/CVE-2026-57432, https://ubuntu.com/security/CVE-2026-57433
Affected packages
Package
Name: perl
Purl: pkg:deb/ubuntu/perl?arch=source&distro=noble
Affected ranges
Type: ECOSYSTEM
Events:
