Skip to content
SUSE Perl Important Heap Overflow Issues Fixed in Advisory 2026

SUSE Perl Important Heap Overflow Issues Fixed in Advisory 2026

Linuxsecurity LinuxSecurity Advisories August 11, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

## This update for perl fixes the following issues * CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date (bsc#1266361). * CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). * CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). * CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out- of-bounds heap read in `pack` and `unpack` (bsc#1271372). * CVE-2026-13221: regex trie branch-count overflow leads to silent false- positive/negative pattern matching (bsc#1271386). ## Patch Instructions:

## This update for perl fixes the following issues * CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date (bsc#1266361). * CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). * CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). * CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out- of-bounds heap read in `pack` and `unpack` (bsc#1271372). * CVE-2026-13221: regex trie branch-count overflow leads to silent false- positive/negative pattern matching (bsc#1271386). ## Patch Instructions:

* CVE-2025-15649 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-15649 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-12087 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

* CVE-2026-12087 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

* CVE-2026-13221 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2026-13221 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2026-13221 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Announcement ID: SUSE-SU-2026:23008-1 Release Date: 2026-07-28T06:50:09Z Rating: important

Get the latest Linux and open source security news straight to your inbox.