[CLSA-2026:1788334635] Fix CVE(s): CVE-2026-57433, CVE-2026-9538
Type:
security
Severity:
Important
Release date:
2026-09-02 07:37:26 UTC
Description:
* SECURITY UPDATE: denial of service via signed integer overflow when deserializing a crafted Storable blob - debian/patches/fixes/CVE-2026-57433.patch: reject a hook data item count of I32_MAX in retrieve_hook_common() in dist/Storable/Storable.xs before it is incremented and passed to av_extend(); backported from upstream commit e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7. - CVE-2026-57433
Updated packages:
  • libperl-dev_5.28.1-6+deb10u1+tuxcare.els7_amd64.deb
    sha:8ef010550364b20765810fc7ff5632d45f038727
  • libperl5.28_5.28.1-6+deb10u1+tuxcare.els7_amd64.deb
    sha:907ececa8fabb7f1c3196b958da0603c0ddb4a97
  • perl_5.28.1-6+deb10u1+tuxcare.els7_amd64.deb
    sha:d037f4915f17fdfe2c66b1708b95117657ee920f
  • perl-base_5.28.1-6+deb10u1+tuxcare.els7_amd64.deb
    sha:b12a1a9b0ea7bd3699b443ac470b145c1227373d
  • perl-debug_5.28.1-6+deb10u1+tuxcare.els7_amd64.deb
    sha:381d65fcc4765012fc765501f23b3cdb5508bc4d
  • perl-doc_5.28.1-6+deb10u1+tuxcare.els7_all.deb
    sha:6415da69af0fb88709be9164281287fd4d7c34ce
  • perl-modules-5.28_5.28.1-6+deb10u1+tuxcare.els7_all.deb
    sha:19e6c892d7082f82a77e7456c18c597da94d9765
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.