Your message dated Mon, 17 Aug 2026 21:19:13 +0000
with message-id <[email protected]>
and subject line Bug#1138861: fixed in perl 5.42.3-1
has caused the Debian Bug report #1138861,
regarding Archive-Tar: CVE-2026-9538
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1138861: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138861
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: perl
Version: 5.40.1-6
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected]
Forwarded:
https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7
Control: found -1 5.32.1-4
Control: found -1 5.36.0-1
Control: found -1 5.42.2-1
The following vulnerability was published[0] for Archive-Tar (bundled with
perl):
CVE ID: CVE-2026-9538
Distribution: Archive-Tar
Versions: before 3.10
MetaCPAN: https://metacpan.org/dist/Archive-Tar
VCS Repo: https://github.com/jib/archive-tar-new
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via
attacker controlled entry size field in tar header
Description
-----------
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via
attacker controlled entry size field in tar header.
_read_tar() reads each entry's payload with $handle->read($$data,
$block), where $block is derived from the entry's 12-byte size field in
the tar header with no upper bound on that value.
A crafted header declaring a multi-gigabyte size causes Perl to
allocate a scalar of that size.
[0] https://lists.security.metacpan.org/cve-announce/msg/40396448/
--
Niko Tyni [email protected]
--- End Message ---
--- Begin Message ---
Source: perl
Source-Version: 5.42.3-1
Done: Niko Tyni <[email protected]>
We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Niko Tyni <[email protected]> (supplier of updated perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA384
Format: 1.8
Date: Mon, 17 Aug 2026 22:59:18 +0300
Source: perl
Architecture: source
Version: 5.42.3-1
Distribution: unstable
Urgency: medium
Maintainer: Niko Tyni <[email protected]>
Changed-By: Niko Tyni <[email protected]>
Closes: 1138859 1138860 1138861 1140152 1141639 1142037
Changes:
perl (5.42.3-1) unstable; urgency=medium
.
* Update to new upstream version 5.42.3.
* [SECURITY] includes various upstream fixes:
+ CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.
(Closes: #1141639)
+ CVE-2026-9538: Archive::Tar memory exhaustion.
(Closes: #1138861)
+ CVE-2026-42496: Archive::Tar symlink extraction.
(Closes: #1138860)
+ CVE-2026-42497: Archive::Tar hardlink extraction.
(Closes: #1138859)
+ CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.
(Closes: #1140152)
+ CVE-2026-13221: silently incorrect regular expression matches.
(Closes: #1142037)
* Refresh cross support files for all architectures.
+ also update the architecture lists in d/cross/README
* Disable salsa-ci.yml as nobody currently cares about the results.
* Update debian/copyright based on DFSG team review.
Checksums-Sha1:
a312494e84f08a1bd4a29edeae6dd7af59e06b1c 2372 perl_5.42.3-1.dsc
1dcede801d09bd47ad351fb4d6280edd879772ed 421372
perl_5.42.3.orig-regen-configure.tar.xz
1d878802a55eacc778bb1d84b1f1b8ab9b22cc96 14495300 perl_5.42.3.orig.tar.xz
5d3bc13b5f9b7b0a8093a466e26f37003c922a34 168064 perl_5.42.3-1.debian.tar.xz
c533e6406fe5a3ab42f5a5814a4f5bbe61fc0435 5338 perl_5.42.3-1_source.buildinfo
Checksums-Sha256:
36535968b24b1f73ce1cf980208017dbe4a38bff5b501cd752e82139206282f7 2372
perl_5.42.3-1.dsc
5ae2aea5bc800c05324e4c9b166391b17368d10300c036fbe45f8c23a799c355 421372
perl_5.42.3.orig-regen-configure.tar.xz
c9387e1473a1866935cb047ece7c2e0a80767a3acdecb79d4a375f8a95970ddc 14495300
perl_5.42.3.orig.tar.xz
0b5692654b3efe8be7e469be851ac8abf6a425bba7c2be5a29a0d553a450956f 168064
perl_5.42.3-1.debian.tar.xz
71408f9f725faa3539ed2d98c1b0f269a4f4d8064daebd44cb891fa0aff2cee4 5338
perl_5.42.3-1_source.buildinfo
Files:
20b760b76e6048cab15d794225bbb2fb 2372 perl standard perl_5.42.3-1.dsc
78cfa5d6df88d464bb118092b5722419 421372 perl standard
perl_5.42.3.orig-regen-configure.tar.xz
fb96e6cf064bf374e84ef232b0eda5c1 14495300 perl standard perl_5.42.3.orig.tar.xz
c03a130c2f86e55c9eb492a835f0a4cf 168064 perl standard
perl_5.42.3-1.debian.tar.xz
1ac4284e689b699f60caca7504d2e3e7 5338 perl standard
perl_5.42.3-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCaoNvcxEcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5srEgAX0RXoXPd0TqEsji+TWA40DTRHIvi9ctyYY/
QA5rNIMgACSGInRTA9LfgfGxHVz828IBgK4HCkE8j9XTfT5LwEGP2a0kwmoCEULu
U9DCNBdol5tJx8F0xbiRPCADcrM7ZZAxhg==
=GdB3
-----END PGP SIGNATURE-----
pgpIjNQBg50tO.pgp
Description: PGP signature
--- End Message ---