Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.3

CVE-2026-8376: Perl may be compromised by crafted regex patterns

CVE-2026-8376 · published 4 months ago
Summary

Perl versions before the latest releases can overflow memory when they compile certain regular expressions that contain a repeated fixed string, but only on 32‑bit installations. This flaw could let an attacker cause the program to crash or potentially run unwanted code. Update Perl to the newest version available for your distribution to eliminate the risk.

What to do
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.7.
  • Update debian rootio-perl to version 5.40.1-6.root.io.2.
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.8.
  • Update debian rootio-perl to version 5.40.1-6.root.io.3.
  • Update canonical perl to version 5.18.2-2ubuntu1.7+esm7.
  • Update canonical perl to version 5.26.1-6ubuntu0.7+esm2.
  • Update canonical perl to version 5.30.0-9ubuntu0.5+esm2.
  • Update canonical perl to version 5.34.0-3ubuntu1.7.
  • Update canonical perl to version 5.38.2-3.2ubuntu0.3.
  • Update canonical perl to version 5.40.1-7ubuntu0.1.
  • Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.2.
  • Update debian perl to version 5.40.1-8.
  • Update debian perl to version 5.32.1-4+deb11u5.root.io.4.
  • Update debian perl to version 5.40.1-6.root.io.4.
  • Update alpine perl to version 5.42.2-r00071.
  • Update alpine rootio-perl to version 5.42.2-r00071.
  • Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.4.
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.9.
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.10.
  • Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.12.
  • Update debian perl to version 5.36.0-7+deb12u3.root.io.12.
  • Update debian rootio-perl to version 5.40.1-6.root.io.1.
  • Update debian rootio-perl to version 5.40.1-6.root.io.4.
  • Update rootio-perl to version 5.40.4-r00072.
  • Update perl to version 5.40.4-r00072.
  • Update perl to version 5.42.2-r00072.
  • Update rootio-perl to version 5.42.2-r00072.
  • Update canonical perl to version 5.40.1-6ubuntu0.1.
  • Update perl to version 5.40.1-6.root.io.4.
  • Update rootio-perl to version 5.40.1-6.root.io.4.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian perl All versions
Debian:12 debian perl All versions
Debian:13 debian perl All versions
Debian:14 debian perl < 5.40.1-8
Fix: upgrade to 5.40.1-8
Ubuntu:Pro:14.04:LTS canonical perl < 5.18.2-2ubuntu1.7+esm7
Fix: upgrade to 5.18.2-2ubuntu1.7+esm7
Ubuntu:Pro:16.04:LTS canonical perl All versions
Ubuntu:18.04:LTS canonical perl All versions
Ubuntu:20.04:LTS canonical perl All versions
Ubuntu:22.04:LTS canonical perl < 5.34.0-3ubuntu1.7
Fix: upgrade to 5.34.0-3ubuntu1.7
Ubuntu:24.04:LTS canonical perl < 5.38.2-3.2ubuntu0.3
Fix: upgrade to 5.38.2-3.2ubuntu0.3
Ubuntu:25.10 canonical perl < 5.40.1-6ubuntu0.1
Fix: upgrade to 5.40.1-6ubuntu0.1
Ubuntu:26.04:LTS canonical perl < 5.40.1-7ubuntu0.1
Fix: upgrade to 5.40.1-7ubuntu0.1
– perl perl <= 5.43.10
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*
Root:Debian:12 debian rootio-perl < 5.36.0-7+deb12u3.root.io.7
< 5.36.0-7+deb12u3.root.io.8
< 5.36.0-7+deb12u3.root.io.9
< 5.36.0-7+deb12u3.root.io.10
< 5.36.0-7+deb12u3.root.io.12
Fix: upgrade to 5.36.0-7+deb12u3.root.io.7
Root:Debian:13 debian rootio-perl < 5.40.1-6.root.io.2
< 5.40.1-6.root.io.3
< 5.40.1-6.root.io.1
< 5.40.1-6.root.io.4
Fix: upgrade to 5.40.1-6.root.io.2
Ubuntu:Pro:18.04:LTS canonical perl < 5.26.1-6ubuntu0.7+esm2
Fix: upgrade to 5.26.1-6ubuntu0.7+esm2
Ubuntu:Pro:20.04:LTS canonical perl < 5.30.0-9ubuntu0.5+esm2
Fix: upgrade to 5.30.0-9ubuntu0.5+esm2
Root:Debian:11 debian rootio-perl < 5.32.1-4+deb11u5.root.io.2
< 5.32.1-4+deb11u5.root.io.4
Fix: upgrade to 5.32.1-4+deb11u5.root.io.2
Root:Debian:11 debian perl < 5.32.1-4+deb11u5.root.io.4
Fix: upgrade to 5.32.1-4+deb11u5.root.io.4
Root:Debian:13 debian perl < 5.40.1-6.root.io.4
Fix: upgrade to 5.40.1-6.root.io.4
Root:Alpine:3.23 alpine perl < 5.42.2-r00071
Fix: upgrade to 5.42.2-r00071
Root:Alpine:3.23 alpine rootio-perl < 5.42.2-r00071
Fix: upgrade to 5.42.2-r00071
Root:Debian:12 debian perl < 5.36.0-7+deb12u3.root.io.12
Fix: upgrade to 5.36.0-7+deb12u3.root.io.12
Root:Alpine:3.22 – rootio-perl < 5.40.4-r00072
Fix: upgrade to 5.40.4-r00072
Root:Alpine:3.22 – perl < 5.40.4-r00072
Fix: upgrade to 5.40.4-r00072
Root:Alpine:3.23 – perl < 5.42.2-r00072
Fix: upgrade to 5.42.2-r00072
Root:Alpine:3.23 – rootio-perl < 5.42.2-r00072
Fix: upgrade to 5.42.2-r00072
Root:Debian:13 – perl < 5.40.1-6.root.io.4
Fix: upgrade to 5.40.1-6.root.io.4
Root:Debian:13 – rootio-perl < 5.40.1-6.root.io.4
Fix: upgrade to 5.40.1-6.root.io.4
Original advisory text
CVE-2026-8376 in perl - Patched by Root
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.
Severity
7.3 High
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-680Integer Overflow to Buffer Overflow
Timeline
Published26 May 2026
Updated25 Sep 2026
First seen21 May 2026
Track software like this
Free during beta