USN-8684-1: Perl vulnerabilities
Publication date
27 August 2026
Overview
Perl could be made to crash or run programs as your login if it opened a specially crafted file.
Releases
Packages
- perl - Practical Extraction and Report Language
Details
It was discovered that Perl incorrectly handled certain arguments to
Socket and pack/unpack functions. An attacker could possibly use this
issue to read sensitive information from memory.
(CVE-2026-12087, CVE-2026-57432)
It was discovered that Perl incorrectly handled regular expressions
with a large number of alternation branches. An attacker could
possibly use this issue to cause incorrect matching results.
(CVE-2026-13221)
It was discovered that Perl incorrectly handled certain files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-57433, CVE-2025-15649, CVE-2026-48959, CVE-2026-9538)
It was discovered that Perl incorrectly...
It was discovered that Perl incorrectly handled certain arguments to
Socket and pack/unpack functions. An attacker could possibly use this
issue to read sensitive information from memory.
(CVE-2026-12087, CVE-2026-57432)
It was discovered that Perl incorrectly handled regular expressions
with a large number of alternation branches. An attacker could
possibly use this issue to cause incorrect matching results.
(CVE-2026-13221)
It was discovered that Perl incorrectly handled certain files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-57433, CVE-2025-15649, CVE-2026-48959, CVE-2026-9538)
It was discovered that Perl incorrectly handled certain inputs. An
attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-48962)
It was discovered that Perl incorrectly handled credential headers
during cross-origin redirects in HTTP::Tiny. An attacker could
possibly use this issue to expose sensitive information.
(CVE-2026-7017)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 24.04 LTS noble | perl – 5.38.2-3.2ubuntu0.4 | ||
| perl-modules-5.38 – 5.38.2-3.2ubuntu0.4 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.