Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.3
CVE-2026-8376: Perl may be compromised by crafted regex patterns
CVE-2026-8376 · published 4 months ago
Summary
Perl versions before the latest releases can overflow memory when they compile certain regular expressions that contain a repeated fixed string, but only on 32‑bit installations. This flaw could let an attacker cause the program to crash or potentially run unwanted code. Update Perl to the newest version available for your distribution to eliminate the risk.
What to do
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.7.
- Update debian rootio-perl to version 5.40.1-6.root.io.2.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.8.
- Update debian rootio-perl to version 5.40.1-6.root.io.3.
- Update canonical perl to version 5.18.2-2ubuntu1.7+esm7.
- Update canonical perl to version 5.26.1-6ubuntu0.7+esm2.
- Update canonical perl to version 5.30.0-9ubuntu0.5+esm2.
- Update canonical perl to version 5.34.0-3ubuntu1.7.
- Update canonical perl to version 5.38.2-3.2ubuntu0.3.
- Update canonical perl to version 5.40.1-7ubuntu0.1.
- Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.2.
- Update debian perl to version 5.40.1-8.
- Update debian perl to version 5.32.1-4+deb11u5.root.io.4.
- Update debian perl to version 5.40.1-6.root.io.4.
- Update alpine perl to version 5.42.2-r00071.
- Update alpine rootio-perl to version 5.42.2-r00071.
- Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.4.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.9.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.10.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.12.
- Update debian perl to version 5.36.0-7+deb12u3.root.io.12.
- Update debian rootio-perl to version 5.40.1-6.root.io.1.
- Update debian rootio-perl to version 5.40.1-6.root.io.4.
- Update rootio-perl to version 5.40.4-r00072.
- Update perl to version 5.40.4-r00072.
- Update perl to version 5.42.2-r00072.
- Update rootio-perl to version 5.42.2-r00072.
- Update canonical perl to version 5.40.1-6ubuntu0.1.
- Update perl to version 5.40.1-6.root.io.4.
- Update rootio-perl to version 5.40.1-6.root.io.4.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | perl | All versions |
| Debian:12 | debian | perl | All versions |
| Debian:13 | debian | perl | All versions |
| Debian:14 | debian | perl |
< 5.40.1-8 Fix: upgrade to 5.40.1-8
|
| Ubuntu:Pro:14.04:LTS | canonical | perl |
< 5.18.2-2ubuntu1.7+esm7 Fix: upgrade to 5.18.2-2ubuntu1.7+esm7
|
| Ubuntu:Pro:16.04:LTS | canonical | perl | All versions |
| Ubuntu:18.04:LTS | canonical | perl | All versions |
| Ubuntu:20.04:LTS | canonical | perl | All versions |
| Ubuntu:22.04:LTS | canonical | perl |
< 5.34.0-3ubuntu1.7 Fix: upgrade to 5.34.0-3ubuntu1.7
|
| Ubuntu:24.04:LTS | canonical | perl |
< 5.38.2-3.2ubuntu0.3 Fix: upgrade to 5.38.2-3.2ubuntu0.3
|
| Ubuntu:25.10 | canonical | perl |
< 5.40.1-6ubuntu0.1 Fix: upgrade to 5.40.1-6ubuntu0.1
|
| Ubuntu:26.04:LTS | canonical | perl |
< 5.40.1-7ubuntu0.1 Fix: upgrade to 5.40.1-7ubuntu0.1
|
| – | perl | perl |
<= 5.43.10 cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:* |
| Root:Debian:12 | debian | rootio-perl |
< 5.36.0-7+deb12u3.root.io.7 < 5.36.0-7+deb12u3.root.io.8 < 5.36.0-7+deb12u3.root.io.9 < 5.36.0-7+deb12u3.root.io.10 < 5.36.0-7+deb12u3.root.io.12 Fix: upgrade to 5.36.0-7+deb12u3.root.io.7
|
| Root:Debian:13 | debian | rootio-perl |
< 5.40.1-6.root.io.2 < 5.40.1-6.root.io.3 < 5.40.1-6.root.io.1 < 5.40.1-6.root.io.4 Fix: upgrade to 5.40.1-6.root.io.2
|
| Ubuntu:Pro:18.04:LTS | canonical | perl |
< 5.26.1-6ubuntu0.7+esm2 Fix: upgrade to 5.26.1-6ubuntu0.7+esm2
|
| Ubuntu:Pro:20.04:LTS | canonical | perl |
< 5.30.0-9ubuntu0.5+esm2 Fix: upgrade to 5.30.0-9ubuntu0.5+esm2
|
| Root:Debian:11 | debian | rootio-perl |
< 5.32.1-4+deb11u5.root.io.2 < 5.32.1-4+deb11u5.root.io.4 Fix: upgrade to 5.32.1-4+deb11u5.root.io.2
|
| Root:Debian:11 | debian | perl |
< 5.32.1-4+deb11u5.root.io.4 Fix: upgrade to 5.32.1-4+deb11u5.root.io.4
|
| Root:Debian:13 | debian | perl |
< 5.40.1-6.root.io.4 Fix: upgrade to 5.40.1-6.root.io.4
|
| Root:Alpine:3.23 | alpine | perl |
< 5.42.2-r00071 Fix: upgrade to 5.42.2-r00071
|
| Root:Alpine:3.23 | alpine | rootio-perl |
< 5.42.2-r00071 Fix: upgrade to 5.42.2-r00071
|
| Root:Debian:12 | debian | perl |
< 5.36.0-7+deb12u3.root.io.12 Fix: upgrade to 5.36.0-7+deb12u3.root.io.12
|
| Root:Alpine:3.22 | – | rootio-perl |
< 5.40.4-r00072 Fix: upgrade to 5.40.4-r00072
|
| Root:Alpine:3.22 | – | perl |
< 5.40.4-r00072 Fix: upgrade to 5.40.4-r00072
|
| Root:Alpine:3.23 | – | perl |
< 5.42.2-r00072 Fix: upgrade to 5.42.2-r00072
|
| Root:Alpine:3.23 | – | rootio-perl |
< 5.42.2-r00072 Fix: upgrade to 5.42.2-r00072
|
| Root:Debian:13 | – | perl |
< 5.40.1-6.root.io.4 Fix: upgrade to 5.40.1-6.root.io.4
|
| Root:Debian:13 | – | rootio-perl |
< 5.40.1-6.root.io.4 Fix: upgrade to 5.40.1-6.root.io.4
|
Original advisory text
CVE-2026-8376 in perl - Patched by Root
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.
References
- https://docs.bell-sw.com/security/cves/CVE-2026-8376 Vendor Advisory
- https://cpan.org/modules URL
- http://www.openwall.com/lists/oss-security/2026/05/26/1 Mailing List Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8376.j... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-8376 Vendor Advisory
- https://github.com/Perl/perl5 Product
- https://security-tracker.debian.org/tracker/CVE-2026-8376 Vendor Advisory
- https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.pa... Patch
- https://ubuntu.com/security/CVE-2026-8376 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-8376 Third Party Advisory
- https://github.com/Perl/perl5/pull/24433 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8467-1 Vendor Advisory
Severity
7.3
High
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-680Integer Overflow to Buffer Overflow
Timeline
Published26 May 2026
Updated25 Sep 2026
First seen21 May 2026
Sources
BELL-CVE-2026-8376 · OSV
DEBIAN-CVE-2026-8376 · OSV
UBUNTU-CVE-2026-8376 · OSV
CVE-2026-8376 · NVD
CVE-2026-8376 · OSV
Track software like this
Free during beta