Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

openSUSE perl-Cpanel-JSON-XS Critical DoS Buffer Overflow Vuln 2026-21140-1

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
This critical update for openSUSE addresses and resolves multiple vulnerabilities in perl-Cpanel-JSON-XS.
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

Description

This update for perl-Cpanel-JSON-XS fixes the following issues:

Changes in perl-Cpanel-JSON-XS:

- updated to 4.420.0 (4.42)

see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes

4.42 2026-06-27 (rurban)

- Ensure encode with a type spec hashref does not change the hashref argument (GH #240)

- Fix -e docs: "written" → "read" (GH #239, reported by Ron Savage).

- Fix Boolean eq overload matching undef (GH #207, reported by fd-t).

Cpanel::JSON::XS::Boolean overloaded eq would match undef as equal

to false because undef stringifies to "". Added defined() guard.

- Fix error messages showing overloaded stringification for blessed

objects (GH #191, reported by karenetheridge). Error messages now

use ClassName=TYPE(addr) format, bypassing any "" overload.

- Fix type_all_string overriding allow_blessed/convert_blessed (GH #175,

reported by alpha6). With type_all_string +...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

perl-Cpanel-JSON-XS-4.420.0-bp160.1.1

References

* bsc#1249331

* bsc#1267546

* bsc#1267547

References:

* https://www.suse.com/security/cve/CVE-2025-40929.html

* https://www.suse.com/security/cve/CVE-2026-9334.html

* https://www.suse.com/security/cve/CVE-2026-9516.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21140-1
Rating: critical
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here