From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
To: openembedded-core@lists.openembedded.org
Cc: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Subject: [wrynose][PATCH 1/2] perl: fix CVE-2026-13221
Date: Tue, 21 Jul 2026 15:45:42 +0200 [thread overview]
Message-ID: <20260721134543.16442-2-jaipaul.cheernam@est.tech> (raw)
In-Reply-To: <20260721134543.16442-1-jaipaul.cheernam@est.tech>
This patch applies the upstream fix as referenced in [1], using the
commit shown in [2].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-13221
[2] https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../perl/files/CVE-2026-13221.patch | 75 +++++++++++++++++++
meta/recipes-devtools/perl/perl_5.42.0.bb | 1 +
2 files changed, 76 insertions(+)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-13221.patch b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch
new file mode 100644
index 0000000000..03396f3e43
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch
@@ -0,0 +1,75 @@
+From 03f74bbbd3a68350d926ee93d56ee4808c28c4c7 Mon Sep 17 00:00:00 2001
+From: Karl Williamson <khw@cpan.org>
+Date: Thu, 26 Mar 2026 10:13:49 -0600
+Subject: [PATCH] regcomp_study: Don't create a trie that would overflow
+
+This addresses GH #23388
+
+The design of the trie compiling code is to batch extra long tries into
+smaller chunks that fit into whatever limitations there are. However,
+this ticket shows that that isn't always being done.
+
+In this case, a bunch of branches that have TAIL operands can be
+combined together, and the final TAIL is used. And the code requires
+that the delta between the first branch and this final TAIL fit into a
+16-bit field. That is the root cause of this bug.
+
+I'm not familiar enough with the trie construction code to easily
+understand why the final tail needs to be used here. So this patch
+simply doesn't optimize a sequence of branches into a trie that would
+overflow.
+
+This could be revisited by someone who knows more about this than I, or
+earlier in the development cycle.
+
+CVE: CVE-2026-13221
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ regcomp_study.c | 10 ++++++++++
+ t/re/pat_advanced.t | 9 +++++++++
+ 2 files changed, 19 insertions(+)
+
+diff --git a/regcomp_study.c b/regcomp_study.c
+index db7ab3a409..a1b2c3d4e5 100644
+--- a/regcomp_study.c
++++ b/regcomp_study.c
+@@ -1933,6 +1933,16 @@ Perl_study_chunk(pTHX_
+ tail = regnext( tail );
+ }
+
++ /* The code below currently saves the difference from
++ * start to finish in a 16-bit field, causing
++ * GH #23388. This defeats the design of batching
++ * tries into chunks that each fit. khw thinks it is
++ * too late in the 5.44 cycle to relook at the design,
++ * so for now anyway, don't make a trie that would
++ * overflow */
++ if (tail - startbranch >= U16_MAX) {
++ continue;
++ }
+
+ DEBUG_TRIE_COMPILE_r({
+ regprop(RExC_rx, RExC_mysv, tail, NULL, pRExC_state);
+diff --git a/t/re/pat_advanced.t b/t/re/pat_advanced.t
+index 398680838d..c9e389ecb3 100644
+--- a/t/re/pat_advanced.t
++++ b/t/re/pat_advanced.t
+@@ -4898,6 +4898,15 @@ EOF_DEBUG_OUT
+ $x =~ s/^[\x{0301}\x{030C}]+//;
+ }
+
++ { # GH #23388
++ fresh_perl_is(<<~'PROG', , "", {}, "Avoid trie overflow");
++ my $x = join "|", "aaa".."mzz";
++ my $y = join "|", "naa".."zzz";
++ use re 'Debug';
++ "fnord" =~ m/(?:$x)|(?:$y)/;
++ PROG
++ }
++
+
+ # !!! NOTE that tests that aren't at all likely to crash perl should go
+ # a ways above, above these last ones. There's a comment there that, like
+--
+2.43.0
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 1833b7a352..1a3451b747 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -18,6 +18,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
file://0001-cpan-Sys-Syslog-Makefile.PL-Fix-_PATH_LOG-for-determ.patch \
file://CVE-2026-8376-01.patch \
file://CVE-2026-8376-02.patch \
+ file://CVE-2026-13221.patch \
"
SRC_URI:append:class-native = " \
file://perl-configpm-switch.patch \
next prev parent reply other threads:[~2026-07-21 13:46 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-21 13:45 [wrynose][PATCH 0/2] perl: fix multiple CVEs Jaipaul Cheernam
2026-07-21 13:45 ` Jaipaul Cheernam [this message]
2026-07-24 13:37 ` [OE-core] [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Yoann Congal
2026-08-25 4:33 ` Jaipaul Cheernam
2026-07-21 13:45 ` [wrynose][PATCH 2/2] perl: fix CVE-2026-57432 Jaipaul Cheernam
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260721134543.16442-2-jaipaul.cheernam@est.tech \
--to=jaipaul.cheernam@est.tech \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.