Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 539
Alerts This Week
Warning Icon 1 539

SUSE Perl Important Security Update Advisory 2026-22847-1

suse
Calendar Grey July 27, 2026
Scroller Suse
This update addresses five notable issues in perl, enhancing the security of SUSE systems. Install promptly for safety.
A security update for perl has been released addressing five vulnerabilities in SUSE Linux Enterprise Server 16.0 and SAP applications, with details on installation and affected pr...

Summary

## This update for perl fixes the following issues: * CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date (bsc#1266361). * CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). * CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). * CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out- of-bounds heap read in `pack` and `unpack` (bsc#1271372). * CVE-2026-13221: regex trie branch-count overflow leads to silent false- positive/negative pattern matching (bsc#1271386). ## Patch Instructions:

References

* bsc#1266304

* bsc#1266361

* bsc#1268349

* bsc#1271372

* bsc#1271386

Cross-

* CVE-2025-15649

* CVE-2026-12087

* CVE-2026-13221

* CVE-2026-57432

* CVE-2026-8376

CVSS scores:

* CVE-2025-15649 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-15649 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-12087 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

* CVE-2026-12087 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

* CVE-2026-13221 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2026-13221 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2026-13221 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22847-1
Release Date: 2026-07-22T08:44:23Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.