Hi Niko, On Tue, Jul 14, 2026 at 11:06:32AM +0300, Niko Tyni wrote: > Control: retitle 1138906 perl: CVE-2026-57433: Storable signed integer > overflow > Control: forcemerge 1138906 -1 > > On Tue, Jul 14, 2026 at 08:50:40AM +0200, Salvatore Bonaccorso wrote: > > Source: perl > > Version: 5.40.1-8 > > Severity: important > > Tags: security upstream > > X-Debbugs-Cc: [email protected], Debian Security Team > > <[email protected]> > > > > Hi, > > > > The following vulnerability was published for perl. > > > > CVE-2026-57433[0]: > > | Storable versions before 3.41 for Perl have a signed integer > > | overflow when deserializing a crafted SX_HOOK record. > > | retrieve_hook_common reads a signed 32-bit item count from an > > | SX_HOOK record and calls av_extend with that count plus one. A count > > | of I32_MAX wraps the addition to a negative value. A crafted blob > > | passed to thaw or retrieve triggers the overflow; av_extend receives > > | the negative count and dies with a panic, terminating the > > | deserialization. > > > > > > If you fix the vulnerability please also make sure to include the > > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > > > For further information see: > > > > [0] https://security-tracker.debian.org/tracker/CVE-2026-57433 > > https://www.cve.org/CVERecord?id=CVE-2026-57433 > > [1] https://lists.security.metacpan.org/cve-announce/msg/41780100/ > > > > Please adjust the affected versions in the BTS as needed. > > This is #1138906 and is already fixed in testing/unstable (but not in stable > so far.) > > So merging.
Ups, apologies for that! > Salvatore: This didn't have a CVE number earlier. Would you like me to > retroactively add one to d/changelog in a future upload? It is fine, not strictly needed. I made sure to fix the metadata in the security-tracker now. Regards, Salvatore

