Multiple Vulnerabilities in Net::CIDR::Lite Affect Ubuntu Releases

Multiple Vulnerabilities in Net::CIDR::Lite Affect Ubuntu Releases

First seen 9 Jun 2026, 02:56 UTC UbuntuLinuxsecurity 87% similarity 57.8

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were discovered in the Net::CIDR::Lite module, affecting various Ubuntu versions, including 16.04 LTS and 18.04 LTS. The vulnerabilities allow remote attackers to bypass access controls based on IP addresses. Specifically, CVE-2021-47154 involves mishandling of extraneous zero characters in IP address strings, while CVE-2026-40198 and CVE-2026-40199 pertain to improper validation of IPv6 addresses and mishandling of IPv4 mapped IPv6 addresses, respectively. The issues were reported by Dave Rolsky and are critical for systems relying on IP-based access controls. Users are advised to update their systems to mitigate these vulnerabilities. The vulnerabilities were published on April 10, 2026, and March 18, 2024, respectively. The affected systems include Ubuntu 16.04 LTS, 18.04 LTS, and other versions.

Key Points: • Net::CIDR::Lite vulnerabilities allow IP access control bypass. • Affected Ubuntu versions include 16.04 LTS and 18.04 LTS. • Users should update to the latest package versions to mitigate risks.

ThreatCluster AI

Timeline

2024-03-18
CVE-2021-47154 published
Vulnerability discovered in Net::CIDR::Lite related to extraneous zero characters in IP addresses.
Ubuntu
2026-04-10
CVE-2026-40198 and CVE-2026-40199 published
Two vulnerabilities reported in Net::CIDR::Lite affecting IPv6 address handling.
Linuxsecurity
2026-06-08
Security notice issued for Net::CIDR::Lite
Ubuntu released a security notice addressing multiple vulnerabilities in Net::CIDR::Lite.
Ubuntu

Community

Browse all →

Tracked Entities in This Story