Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-42496: Perl on Debian 13 can run unauthorized code
CVE-2026-42496 · published 1 month ago
Summary
The Perl language packages used in Debian 13 (including versions from BellSoft, Archive, Debian and Canonical) contain a flaw that could let an attacker execute code they should not be able to run. This could compromise the security of any system that relies on these Perl packages. Update to the latest patched version of the Perl packages as soon as possible.
What to do
- Update bellsoft perl to version 5.42.2-r1.
- Update debian rootio-perl to version 5.36.0-7+deb12u2.root.io.6.
- Update debian rootio-perl to version 5.40.1-6.root.io.2.
- Update debian rootio-perl to version 5.40.1-6.root.io.3.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.8.
- Update canonical perl to version 5.18.2-2ubuntu1.7+esm7.
- Update canonical perl to version 5.26.1-6ubuntu0.7+esm2.
- Update canonical perl to version 5.30.0-9ubuntu0.5+esm2.
- Update canonical perl to version 5.34.0-3ubuntu1.7.
- Update canonical perl to version 5.38.2-3.2ubuntu0.3.
- Update canonical perl to version 5.40.1-7ubuntu0.1.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.12.
- Update debian perl to version 5.40.1-6.root.io.4.
- Update debian perl to version 5.32.1-4+deb11u5.root.io.4.
- Update debian perl to version 5.42.3-1.
- Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.2.
- Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.4.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.9.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.10.
- Update debian perl to version 5.36.0-7+deb12u3.root.io.12.
- Update debian rootio-perl to version 5.40.1-6.root.io.1.
- Update debian rootio-perl to version 5.40.1-6.root.io.4.
- Update perl to version 5.40.1-6.root.io.4.
- Update rootio-perl to version 5.40.1-6.root.io.4.
- Update archive\ \ to version 3.08 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Alpaquita:23 | bellsoft | perl | >= 5.36.0-r0 |
| Alpaquita:25 | bellsoft | perl | >= 5.40.2-r0 |
| Alpaquita:stream | bellsoft | perl |
>= 5.36.0-r0, < 5.42.2-r1 Fix: upgrade to 5.42.2-r1
|
| – | archive\ | \ |
tar_project cpe:2.3:a:archive\:\:tar_project:archive\:\:tar:*:*:*:*:*:perl:*:* |
| BellSoft Hardened Containers:23 | bellsoft | perl | >= 5.36.0-r0 |
| BellSoft Hardened Containers:25 | bellsoft | perl | >= 5.40.2-r0 |
| BellSoft Hardened Containers:stream | bellsoft | perl |
>= 5.36.0-r0, < 5.42.2-r1 Fix: upgrade to 5.42.2-r1
|
| Debian:11 | debian | perl | All versions |
| Debian:12 | debian | perl | All versions |
| Debian:13 | debian | perl | All versions |
| Debian:14 | debian | perl |
< 5.42.3-1 Fix: upgrade to 5.42.3-1
|
| Root:Debian:12 | debian | rootio-perl |
< 5.36.0-7+deb12u2.root.io.6 < 5.36.0-7+deb12u3.root.io.8 < 5.36.0-7+deb12u3.root.io.12 < 5.36.0-7+deb12u3.root.io.9 < 5.36.0-7+deb12u3.root.io.10 Fix: upgrade to 5.36.0-7+deb12u2.root.io.6
|
| Root:Debian:13 | debian | rootio-perl |
< 5.40.1-6.root.io.2 < 5.40.1-6.root.io.3 < 5.40.1-6.root.io.1 < 5.40.1-6.root.io.4 Fix: upgrade to 5.40.1-6.root.io.2
|
| Ubuntu:Pro:14.04:LTS | canonical | perl |
< 5.18.2-2ubuntu1.7+esm7 Fix: upgrade to 5.18.2-2ubuntu1.7+esm7
|
| Ubuntu:Pro:18.04:LTS | canonical | perl |
< 5.26.1-6ubuntu0.7+esm2 Fix: upgrade to 5.26.1-6ubuntu0.7+esm2
|
| Ubuntu:Pro:20.04:LTS | canonical | perl |
< 5.30.0-9ubuntu0.5+esm2 Fix: upgrade to 5.30.0-9ubuntu0.5+esm2
|
| Ubuntu:22.04:LTS | canonical | perl |
< 5.34.0-3ubuntu1.7 Fix: upgrade to 5.34.0-3ubuntu1.7
|
| Ubuntu:24.04:LTS | canonical | perl |
< 5.38.2-3.2ubuntu0.3 Fix: upgrade to 5.38.2-3.2ubuntu0.3
|
| Ubuntu:25.10 | canonical | perl | All versions |
| Ubuntu:26.04:LTS | canonical | perl |
< 5.40.1-7ubuntu0.1 Fix: upgrade to 5.40.1-7ubuntu0.1
|
| Root:Debian:13 | debian | perl |
< 5.40.1-6.root.io.4 Fix: upgrade to 5.40.1-6.root.io.4
|
| Root:Debian:11 | debian | perl |
< 5.32.1-4+deb11u5.root.io.4 Fix: upgrade to 5.32.1-4+deb11u5.root.io.4
|
| Root:Debian:11 | debian | rootio-perl |
< 5.32.1-4+deb11u5.root.io.2 < 5.32.1-4+deb11u5.root.io.4 Fix: upgrade to 5.32.1-4+deb11u5.root.io.2
|
| Root:Debian:12 | debian | perl |
< 5.36.0-7+deb12u3.root.io.12 Fix: upgrade to 5.36.0-7+deb12u3.root.io.12
|
| Root:Debian:13 | – | perl |
< 5.40.1-6.root.io.4 Fix: upgrade to 5.40.1-6.root.io.4
|
| Root:Debian:13 | – | rootio-perl |
< 5.40.1-6.root.io.4 Fix: upgrade to 5.40.1-6.root.io.4
|
Original advisory text
CVE-2026-42496 in perl - Patched by Root
Root has patched CVE-2026-42496 in the perl package for Root:Debian:13. Multiple fixed versions available.
References
- https://security-tracker.debian.org/tracker/CVE-2026-42496 Vendor Advisory
- https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd... Third Party Advisory
- https://ubuntu.com/security/CVE-2026-42496 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-42496 Third Party Advisory
- https://lists.security.metacpan.org/cve-announce/msg/40396459/ Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json
- https://access.redhat.com/errata/RHSA-2026:30852
- https://access.redhat.com/errata/RHSA-2026:30851
- https://access.redhat.com/errata/RHSA-2026:30856
- https://www.cve.org/CVERecord?id=CVE-2026-42497
- https://bugzilla.redhat.com/show_bug.cgi?id=2481314
- https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes
- https://access.redhat.com/security/cve/CVE-2026-42496
- https://docs.bell-sw.com/security/cves/CVE-2026-42496 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:30857
Severity
9.1
Critical
CVSS 3.1: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-59Link Following
CWE-22Path Traversal
Timeline
Published24 Aug 2026
Updated25 Sep 2026
First seen26 May 2026
Sources
BELL-CVE-2026-42496 · OSV
DEBIAN-CVE-2026-42496 · OSV
CVE-2026-42496 · NVD
UBUNTU-CVE-2026-42496 · OSV
Track software like this
Free during beta