Linuxsecurity Critical Deserialization Vulnerability in Fedora 44 and 45 perl-Dancer2
Article Content
- •Critical deserialization vulnerability affects Fedora 44 and 45 perl-Dancer2.
- •CISA confirms exploitation in the wild, increasing urgency for patching.
- •Immediate updates are available via the dnf package manager.
A major deserialization vulnerability has been identified in the perl-Dancer2 framework affecting Fedora 44 and 45. CISA has confirmed exploitation of this flaw, which allows arbitrary object instantiation through YAML deserialization. The vulnerability arises from the Dancer2::Serializer::YAML::deserialize method, which improperly handles request bodies. This vulnerability is particularly concerning as it can lead to the execution of arbitrary code. The affected versions are perl-Dancer2 2.2.1 in both Fedora 44 and 45. Users are urged to apply the available patches immediately to mitigate the risk. The updates set $YAML::LoadBlessed and $YAML::LoadCode to 0 before loading, addressing the security issue. The updates can be installed using the dnf package manager. As of today, both updates have been released and are available for installation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…