Fix three security vulnerabilities in perl 5.38.4:

- CVE-2026-13221: regex trie overflow causing incorrect matches when
  alternation has more than 65535 fixed string branches (CVSS 9.1)
- CVE-2026-57432: integer overflow in pack/unpack leading to
  out-of-bounds heap read (CVSS 8.4)
- CVE-2025-40909: threads working directory race condition allowing
  file operations to target unintended paths

Changes since v1:
- Added CVE-2025-40909 fix with companion perlcross patch for
  d_fdopendir configuration detection

CVE-2025-40909 is fixed upstream in perl 5.42.0. CVE-2026-13221 and
CVE-2026-57432 are fixed upstream in perl 5.44.0.

Signed-off-by: Jaipaul Cheernam <[email protected]>
---

Changes in v2:
- Added companion perlcross patch (CVE-2025-40909-dep) to add
  d_fdopendir configuration detection required by the CVE fix

Jaipaul Cheernam (3):
  perl: fix CVE-2026-13221
  perl: fix CVE-2026-57432
  perl: fix CVE-2025-40909

 .../perl-cross/files/CVE-2025-40909-dep.patch |  25 ++
 .../perl-cross/perlcross_1.6.2.bb             |   1 +
 .../perl/files/CVE-2025-40909.patch           | 412 ++++++++++++++++++
 .../perl/files/CVE-2026-13221.patch           |  75 ++++
 .../perl/files/CVE-2026-57432-01.patch        |  52 +++
 .../perl/files/CVE-2026-57432-02.patch        |  34 ++
 meta/recipes-devtools/perl/perl_5.38.4.bb     |   4 +
 7 files changed, 603 insertions(+)
 create mode 100644 
meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2025-40909.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241535): 
https://lists.openembedded.org/g/openembedded-core/message/241535
Mute This Topic: https://lists.openembedded.org/mt/120377461/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to