* [wrynose][PATCH 0/2] perl: fix multiple CVEs
@ 2026-07-21 13:45 Jaipaul Cheernam
2026-07-21 13:45 ` [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Jaipaul Cheernam
2026-07-21 13:45 ` [wrynose][PATCH 2/2] perl: fix CVE-2026-57432 Jaipaul Cheernam
0 siblings, 2 replies; 5+ messages in thread
From: Jaipaul Cheernam @ 2026-07-21 13:45 UTC (permalink / raw)
To: openembedded-core; +Cc: Jaipaul Cheernam
Fix two security vulnerabilities in perl 5.42.0:
- CVE-2026-13221: regex trie overflow causing incorrect matches when
alternation has more than 65535 fixed string branches (CVSS 9.1)
- CVE-2026-57432: integer overflow in pack/unpack leading to
out-of-bounds heap read (CVSS 8.4)
Both are fixed upstream in perl 5.44.0.
Jaipaul Cheernam (2):
perl: fix CVE-2026-13221
perl: fix CVE-2026-57432
.../perl/files/CVE-2026-13221.patch | 75 +++++++++++++++++++
.../perl/files/CVE-2026-57432-01.patch | 52 +++++++++++++
.../perl/files/CVE-2026-57432-02.patch | 34 +++++++++
meta/recipes-devtools/perl/perl_5.42.0.bb | 3 +
4 files changed, 164 insertions(+)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
^ permalink raw reply [flat|nested] 5+ messages in thread
* [wrynose][PATCH 1/2] perl: fix CVE-2026-13221
2026-07-21 13:45 [wrynose][PATCH 0/2] perl: fix multiple CVEs Jaipaul Cheernam
@ 2026-07-21 13:45 ` Jaipaul Cheernam
2026-07-24 13:37 ` [OE-core] " Yoann Congal
2026-07-21 13:45 ` [wrynose][PATCH 2/2] perl: fix CVE-2026-57432 Jaipaul Cheernam
1 sibling, 1 reply; 5+ messages in thread
From: Jaipaul Cheernam @ 2026-07-21 13:45 UTC (permalink / raw)
To: openembedded-core; +Cc: Jaipaul Cheernam
This patch applies the upstream fix as referenced in [1], using the
commit shown in [2].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-13221
[2] https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../perl/files/CVE-2026-13221.patch | 75 +++++++++++++++++++
meta/recipes-devtools/perl/perl_5.42.0.bb | 1 +
2 files changed, 76 insertions(+)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-13221.patch b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch
new file mode 100644
index 0000000000..03396f3e43
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch
@@ -0,0 +1,75 @@
+From 03f74bbbd3a68350d926ee93d56ee4808c28c4c7 Mon Sep 17 00:00:00 2001
+From: Karl Williamson <khw@cpan.org>
+Date: Thu, 26 Mar 2026 10:13:49 -0600
+Subject: [PATCH] regcomp_study: Don't create a trie that would overflow
+
+This addresses GH #23388
+
+The design of the trie compiling code is to batch extra long tries into
+smaller chunks that fit into whatever limitations there are. However,
+this ticket shows that that isn't always being done.
+
+In this case, a bunch of branches that have TAIL operands can be
+combined together, and the final TAIL is used. And the code requires
+that the delta between the first branch and this final TAIL fit into a
+16-bit field. That is the root cause of this bug.
+
+I'm not familiar enough with the trie construction code to easily
+understand why the final tail needs to be used here. So this patch
+simply doesn't optimize a sequence of branches into a trie that would
+overflow.
+
+This could be revisited by someone who knows more about this than I, or
+earlier in the development cycle.
+
+CVE: CVE-2026-13221
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ regcomp_study.c | 10 ++++++++++
+ t/re/pat_advanced.t | 9 +++++++++
+ 2 files changed, 19 insertions(+)
+
+diff --git a/regcomp_study.c b/regcomp_study.c
+index db7ab3a409..a1b2c3d4e5 100644
+--- a/regcomp_study.c
++++ b/regcomp_study.c
+@@ -1933,6 +1933,16 @@ Perl_study_chunk(pTHX_
+ tail = regnext( tail );
+ }
+
++ /* The code below currently saves the difference from
++ * start to finish in a 16-bit field, causing
++ * GH #23388. This defeats the design of batching
++ * tries into chunks that each fit. khw thinks it is
++ * too late in the 5.44 cycle to relook at the design,
++ * so for now anyway, don't make a trie that would
++ * overflow */
++ if (tail - startbranch >= U16_MAX) {
++ continue;
++ }
+
+ DEBUG_TRIE_COMPILE_r({
+ regprop(RExC_rx, RExC_mysv, tail, NULL, pRExC_state);
+diff --git a/t/re/pat_advanced.t b/t/re/pat_advanced.t
+index 398680838d..c9e389ecb3 100644
+--- a/t/re/pat_advanced.t
++++ b/t/re/pat_advanced.t
+@@ -4898,6 +4898,15 @@ EOF_DEBUG_OUT
+ $x =~ s/^[\x{0301}\x{030C}]+//;
+ }
+
++ { # GH #23388
++ fresh_perl_is(<<~'PROG', , "", {}, "Avoid trie overflow");
++ my $x = join "|", "aaa".."mzz";
++ my $y = join "|", "naa".."zzz";
++ use re 'Debug';
++ "fnord" =~ m/(?:$x)|(?:$y)/;
++ PROG
++ }
++
+
+ # !!! NOTE that tests that aren't at all likely to crash perl should go
+ # a ways above, above these last ones. There's a comment there that, like
+--
+2.43.0
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 1833b7a352..1a3451b747 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -18,6 +18,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
file://0001-cpan-Sys-Syslog-Makefile.PL-Fix-_PATH_LOG-for-determ.patch \
file://CVE-2026-8376-01.patch \
file://CVE-2026-8376-02.patch \
+ file://CVE-2026-13221.patch \
"
SRC_URI:append:class-native = " \
file://perl-configpm-switch.patch \
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [wrynose][PATCH 2/2] perl: fix CVE-2026-57432
2026-07-21 13:45 [wrynose][PATCH 0/2] perl: fix multiple CVEs Jaipaul Cheernam
2026-07-21 13:45 ` [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Jaipaul Cheernam
@ 2026-07-21 13:45 ` Jaipaul Cheernam
1 sibling, 0 replies; 5+ messages in thread
From: Jaipaul Cheernam @ 2026-07-21 13:45 UTC (permalink / raw)
To: openembedded-core; +Cc: Jaipaul Cheernam
This patch applies the upstream fix as referenced in [1], using the
commits shown in [2] and [3].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57432
[2] https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55
[3] https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../perl/files/CVE-2026-57432-01.patch | 52 +++++++++++++++++++
.../perl/files/CVE-2026-57432-02.patch | 34 ++++++++++++
meta/recipes-devtools/perl/perl_5.42.0.bb | 2 +
3 files changed, 88 insertions(+)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
new file mode 100644
index 0000000000..ef92b0d7b2
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
@@ -0,0 +1,52 @@
+From 5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 Mon Sep 17 00:00:00 2001
+From: "Paul \"LeoNerd\" Evans" <leonerd@leonerd.org.uk>
+Date: Sat, 9 May 2026 17:18:43 +0100
+Subject: [PATCH] pp_pack.c: Avoid ssize_t overflow when calculating the size
+ of a structure
+
+If the user has requested a size that would overflow a SSize_t, then the
+only sensible thing to do is throw an exception, because the structure
+this implies couldn't possibly fit into memory anyway.
+
+CVE: CVE-2026-57432
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ pod/perldiag.pod | 6 ++++++
+ pp_pack.c | 4 ++++
+ 2 files changed, 10 insertions(+)
+
+diff --git a/pod/perldiag.pod b/pod/perldiag.pod
+index 841e22d580..d9231077363d 100644
+--- a/pod/perldiag.pod
++++ b/pod/perldiag.pod
+@@ -4880,6 +4880,12 @@ mixed-case attribute name, instead. See L<attributes>.
+ (F) You can't specify a repeat count so large that it overflows your
+ signed integers. See L<perlfunc/pack>.
+
++=item Pack template structure size is too large
++
++(F) You called C<pack> or C<unpack> to operate on a structure, whose
++computed size is too large to fit in memory. This usually happens as a
++result of embedding a large number as the repeat count for an item.
++
+ =item page overflow
+
+ (W io) A single call to write() produced more lines than can fit on a
+diff --git a/pp_pack.c b/pp_pack.c
+index b5c0b261ef..6075e83aac 100644
+--- a/pp_pack.c
++++ b/pp_pack.c
+@@ -528,6 +528,10 @@ S_measure_struct(pTHX_ tempsym_t* symptr)
+ break;
+ }
+ }
++ if ((size > 0) &&
++ ((len > SSize_t_MAX / size) || /* detect overflow of len * size */
++ (len * size > SSize_t_MAX - total))) /* detect overflow of total + len * size */
++ croak("Pack template structure size is too large");
+ total += len * size;
+ }
+ return total;
+--
+2.43.0
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
new file mode 100644
index 0000000000..273a247a88
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
@@ -0,0 +1,34 @@
+From 40754edc72dd3e513d758153c0e2f0215897740e Mon Sep 17 00:00:00 2001
+From: "Paul \"LeoNerd\" Evans" <leonerd@leonerd.org.uk>
+Date: Mon, 11 May 2026 12:25:33 +0100
+Subject: [PATCH] pp_pack.c: Avoid some other potential overflows when
+ calculating sizes
+
+CVE: CVE-2026-57432
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ pp_pack.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/pp_pack.c b/pp_pack.c
+index 6075e83aac..b2019902203a 100644
+--- a/pp_pack.c
++++ b/pp_pack.c
+@@ -515,12 +515,12 @@ S_measure_struct(pTHX_ tempsym_t* symptr)
+ break;
+ case 'B':
+ case 'b':
+- len = (len + 7)/8;
++ len = (len / 8) + !!(len % 8);
+ size = 1;
+ break;
+ case 'H':
+ case 'h':
+- len = (len + 1)/2;
++ len = (len / 2) + !!(len % 2);
+ size = 1;
+ break;
+
+--
+2.43.0
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 1a3451b747..8716f1f257 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -19,6 +19,8 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
file://CVE-2026-8376-01.patch \
file://CVE-2026-8376-02.patch \
file://CVE-2026-13221.patch \
+ file://CVE-2026-57432-01.patch \
+ file://CVE-2026-57432-02.patch \
"
SRC_URI:append:class-native = " \
file://perl-configpm-switch.patch \
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [OE-core] [wrynose][PATCH 1/2] perl: fix CVE-2026-13221
2026-07-21 13:45 ` [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Jaipaul Cheernam
@ 2026-07-24 13:37 ` Yoann Congal
2026-08-25 4:33 ` Jaipaul Cheernam
0 siblings, 1 reply; 5+ messages in thread
From: Yoann Congal @ 2026-07-24 13:37 UTC (permalink / raw)
To: jaipaul.cheernam, openembedded-core
On Tue Jul 21, 2026 at 3:45 PM CEST, Jaipaul Cheernam via lists.openembedded.org wrote:
> This patch applies the upstream fix as referenced in [1], using the
> commit shown in [2].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-13221
> [2] https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7
>
> Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
> ---
> .../perl/files/CVE-2026-13221.patch | 75 +++++++++++++++++++
> meta/recipes-devtools/perl/perl_5.42.0.bb | 1 +
> 2 files changed, 76 insertions(+)
> create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
Hello,
For my own tracking, this series needs "perl: upgrade 5.42.2 -> 5.44.0"
on master.
Regards,
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [wrynose][PATCH 1/2] perl: fix CVE-2026-13221
2026-07-24 13:37 ` [OE-core] " Yoann Congal
@ 2026-08-25 4:33 ` Jaipaul Cheernam
0 siblings, 0 replies; 5+ messages in thread
From: Jaipaul Cheernam @ 2026-08-25 4:33 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 100 bytes --]
Hi Yoann,
Perl 5.44.0 has been merged to master and can you look on this ?
Regards,
Jaipaul
[-- Attachment #2: Type: text/html, Size: 190 bytes --]
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-08-25 4:33 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-21 13:45 [wrynose][PATCH 0/2] perl: fix multiple CVEs Jaipaul Cheernam
2026-07-21 13:45 ` [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Jaipaul Cheernam
2026-07-24 13:37 ` [OE-core] " Yoann Congal
2026-08-25 4:33 ` Jaipaul Cheernam
2026-07-21 13:45 ` [wrynose][PATCH 2/2] perl: fix CVE-2026-57432 Jaipaul Cheernam
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.