Source: libio-compress-perl Version: 2.219-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for libio-compress-perl. CVE-2026-48961[0]: | IO::Compress versions from 2.207 before 2.220 for Perl ship a | zipdetails CLI tool that crashes with undefined subroutine on Info- | ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in | bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) | with UID Size or GID Size set to 8, causing zipdetails to decode an | 8-byte UID or GID value, it dispatches through decodeLitteEndian(), | which calls a misnamed helper unpackValueQ. The actual function | defined in the same file is unpackValue_Q (with underscore); the | call raises 'Undefined subroutine &main::unpackValueQ' and the | script exits with status 255. Library callers of IO::Compress and | IO::Uncompress are not affected; the defect is in the bundled CLI | tool. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-48961 https://www.cve.org/CVERecord?id=CVE-2026-48961 [1] https://lists.security.metacpan.org/cve-announce/msg/40434383/ [2] https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

