[CLSA-2026:1788175535] Fix CVE(s): CVE-2026-57433
Type:
security
Severity:
Important
Release date:
2026-08-31 11:25:47 UTC
Description:
* SECURITY UPDATE: signed integer overflow when deserializing a crafted Storable SX_HOOK record - debian/patches/CVE-2026-57433.patch: reject a hook data item count of I32_MAX in retrieve_hook() in dist/Storable/Storable.xs before it is incremented and passed to av_extend() - CVE-2026-57433
CVEs fixed:
Updated packages:
  • libperl-dev_5.26.1-6ubuntu0.7+tuxcare.els4_amd64.deb
    sha:814b57aaa2c882f3dcdf7afee44e9d2d17dedac2
  • libperl5.26_5.26.1-6ubuntu0.7+tuxcare.els4_amd64.deb
    sha:4017b8b88b80a8ca9e1b78e3c2de07797b3d64d3
  • perl_5.26.1-6ubuntu0.7+tuxcare.els4_amd64.deb
    sha:6101ffcde26bb34c20fb37cf660adcab99c03902
  • perl-base_5.26.1-6ubuntu0.7+tuxcare.els4_amd64.deb
    sha:d7be075107c9c278d57aeb247bb38bc174ac795e
  • perl-debug_5.26.1-6ubuntu0.7+tuxcare.els4_amd64.deb
    sha:2bf5daa2bf20d772ef75f6f9dce8864b82f54fdc
  • perl-doc_5.26.1-6ubuntu0.7+tuxcare.els4_all.deb
    sha:672c2a998333b753d2254fc0b7c720b28d4cab53
  • perl-modules-5.26_5.26.1-6ubuntu0.7+tuxcare.els4_all.deb
    sha:a6224225fcb858f0488d00c65329388757c30814
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.