Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

openSUSE Leap 16.0 Perl Important Heap Buffer Overflow Vuln 2026-21411-1

opensuse
Calendar Grey July 24, 2026
Scroller Opensuse
This update addresses multiple issues in openSUSE perl, including critical buffer overflows and integer overflows.
openSUSE has released a security update for Perl addressing five vulnerabilities, including critical issues related to heap overflows and integer overflows, affecting openSUSE Leap...

Description

This update for perl fixes the following issues:

- CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date

(bsc#1266361).

- CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds

(bsc#1266304).

- CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure

(bsc#1268349).

- CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack`

(bsc#1271372).

- CVE-2026-13221: regex trie branch-count overflow leads to silent false-positive/negative pattern matching

(bsc#1271386).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

perl-5.42.0-160000.3.1

perl-base-5.42.0-160000.3.1

perl-doc-5.42.0-160000.3.1

References

* bsc#1266304

* bsc#1266361

* bsc#1268349

* bsc#1271372

* bsc#1271386

References:

* https://www.suse.com/security/cve/CVE-2025-15649.html

* https://www.suse.com/security/cve/CVE-2026-12087.html

* https://www.suse.com/security/cve/CVE-2026-13221.html

* https://www.suse.com/security/cve/CVE-2026-57432.html

* https://www.suse.com/security/cve/CVE-2026-8376.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21411-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.