Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for perl fixes the following issues:
- CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date
(bsc#1266361).
- CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
(bsc#1266304).
- CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure
(bsc#1268349).
- CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack`
(bsc#1271372).
- CVE-2026-13221: regex trie branch-count overflow leads to silent false-positive/negative pattern matching
(bsc#1271386).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch...
Read the Full Advisory- openSUSE Leap 16.0:
perl-5.42.0-160000.3.1
perl-base-5.42.0-160000.3.1
perl-doc-5.42.0-160000.3.1
* bsc#1266304
* bsc#1266361
* bsc#1268349
* bsc#1271372
* bsc#1271386
References:
* https://www.suse.com/security/cve/CVE-2025-15649.html
* https://www.suse.com/security/cve/CVE-2026-12087.html
* https://www.suse.com/security/cve/CVE-2026-13221.html
* https://www.suse.com/security/cve/CVE-2026-57432.html
* https://www.suse.com/security/cve/CVE-2026-8376.html
Get the latest Linux and open source security news straight to your inbox.