Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-42496: Perl on Debian 13 can run unauthorized code

CVE-2026-42496 · published 1 month ago
Summary

The Perl language packages used in Debian 13 (including versions from BellSoft, Archive, Debian and Canonical) contain a flaw that could let an attacker execute code they should not be able to run. This could compromise the security of any system that relies on these Perl packages. Update to the latest patched version of the Perl packages as soon as possible.

What to do
  • Update bellsoft perl to version 5.42.2-r1.
  • Update debian rootio-perl to version 5.36.0-7+deb12u2.root.io.6.
  • Update debian rootio-perl to version 5.40.1-6.root.io.2.
  • Update debian rootio-perl to version 5.40.1-6.root.io.3.
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.8.
  • Update canonical perl to version 5.18.2-2ubuntu1.7+esm7.
  • Update canonical perl to version 5.26.1-6ubuntu0.7+esm2.
  • Update canonical perl to version 5.30.0-9ubuntu0.5+esm2.
  • Update canonical perl to version 5.34.0-3ubuntu1.7.
  • Update canonical perl to version 5.38.2-3.2ubuntu0.3.
  • Update canonical perl to version 5.40.1-7ubuntu0.1.
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.12.
  • Update debian perl to version 5.40.1-6.root.io.4.
  • Update debian perl to version 5.32.1-4+deb11u5.root.io.4.
  • Update debian perl to version 5.42.3-1.
  • Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.2.
  • Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.4.
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.9.
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.10.
  • Update debian perl to version 5.36.0-7+deb12u3.root.io.12.
  • Update debian rootio-perl to version 5.40.1-6.root.io.1.
  • Update debian rootio-perl to version 5.40.1-6.root.io.4.
  • Update perl to version 5.40.1-6.root.io.4.
  • Update rootio-perl to version 5.40.1-6.root.io.4.
  • Update archive\ \ to version 3.08 or later.
Affected software
Ecosystem VendorProductAffected versions
Alpaquita:23 bellsoft perl >= 5.36.0-r0
Alpaquita:25 bellsoft perl >= 5.40.2-r0
Alpaquita:stream bellsoft perl >= 5.36.0-r0, < 5.42.2-r1
Fix: upgrade to 5.42.2-r1
– archive\ \ tar_project
cpe:2.3:a:archive\:\:tar_project:archive\:\:tar:*:*:*:*:*:perl:*:*
BellSoft Hardened Containers:23 bellsoft perl >= 5.36.0-r0
BellSoft Hardened Containers:25 bellsoft perl >= 5.40.2-r0
BellSoft Hardened Containers:stream bellsoft perl >= 5.36.0-r0, < 5.42.2-r1
Fix: upgrade to 5.42.2-r1
Debian:11 debian perl All versions
Debian:12 debian perl All versions
Debian:13 debian perl All versions
Debian:14 debian perl < 5.42.3-1
Fix: upgrade to 5.42.3-1
Root:Debian:12 debian rootio-perl < 5.36.0-7+deb12u2.root.io.6
< 5.36.0-7+deb12u3.root.io.8
< 5.36.0-7+deb12u3.root.io.12
< 5.36.0-7+deb12u3.root.io.9
< 5.36.0-7+deb12u3.root.io.10
Fix: upgrade to 5.36.0-7+deb12u2.root.io.6
Root:Debian:13 debian rootio-perl < 5.40.1-6.root.io.2
< 5.40.1-6.root.io.3
< 5.40.1-6.root.io.1
< 5.40.1-6.root.io.4
Fix: upgrade to 5.40.1-6.root.io.2
Ubuntu:Pro:14.04:LTS canonical perl < 5.18.2-2ubuntu1.7+esm7
Fix: upgrade to 5.18.2-2ubuntu1.7+esm7
Ubuntu:Pro:18.04:LTS canonical perl < 5.26.1-6ubuntu0.7+esm2
Fix: upgrade to 5.26.1-6ubuntu0.7+esm2
Ubuntu:Pro:20.04:LTS canonical perl < 5.30.0-9ubuntu0.5+esm2
Fix: upgrade to 5.30.0-9ubuntu0.5+esm2
Ubuntu:22.04:LTS canonical perl < 5.34.0-3ubuntu1.7
Fix: upgrade to 5.34.0-3ubuntu1.7
Ubuntu:24.04:LTS canonical perl < 5.38.2-3.2ubuntu0.3
Fix: upgrade to 5.38.2-3.2ubuntu0.3
Ubuntu:25.10 canonical perl All versions
Ubuntu:26.04:LTS canonical perl < 5.40.1-7ubuntu0.1
Fix: upgrade to 5.40.1-7ubuntu0.1
Root:Debian:13 debian perl < 5.40.1-6.root.io.4
Fix: upgrade to 5.40.1-6.root.io.4
Root:Debian:11 debian perl < 5.32.1-4+deb11u5.root.io.4
Fix: upgrade to 5.32.1-4+deb11u5.root.io.4
Root:Debian:11 debian rootio-perl < 5.32.1-4+deb11u5.root.io.2
< 5.32.1-4+deb11u5.root.io.4
Fix: upgrade to 5.32.1-4+deb11u5.root.io.2
Root:Debian:12 debian perl < 5.36.0-7+deb12u3.root.io.12
Fix: upgrade to 5.36.0-7+deb12u3.root.io.12
Root:Debian:13 – perl < 5.40.1-6.root.io.4
Fix: upgrade to 5.40.1-6.root.io.4
Root:Debian:13 – rootio-perl < 5.40.1-6.root.io.4
Fix: upgrade to 5.40.1-6.root.io.4
Original advisory text
CVE-2026-42496 in perl - Patched by Root
Root has patched CVE-2026-42496 in the perl package for Root:Debian:13. Multiple fixed versions available.
Severity
9.1 Critical
CVSS 3.1: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-59Link Following
CWE-22Path Traversal
Timeline
Published24 Aug 2026
Updated25 Sep 2026
First seen26 May 2026
Track software like this
Free during beta