Views
5

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8675-2 provides the Ubuntu 26.04 LTS fix for Perl vulnerabilities previously addressed in USN-8675-1. It includes security fixes for CVE-2026-12087, CVE-2026-13221, CVE-2026-57432, and CVE-2026-57433.

Update Details

Security

  • Fixed an out-of-bounds heap read in the Socket module caused by short source addresses, which could lead to information disclosure (CVE-2026-12087).
  • Fixed incorrect handling of regular expressions with many fixed string alternatives, which could allow security restrictions to be bypassed (CVE-2026-13221).
  • Fixed incorrect handling of large repeat counts in pack and unpack templates, which could lead to information disclosure via an out-of-bounds heap read (CVE-2026-57432).
  • Fixed an integer overflow in Storable deserialization that could cause application termination and denial of service (CVE-2026-57433).

Hints

  • A standard system update will apply the fixes.
  • For Ubuntu 26.04 LTS, update to libperl5.40 5.40.1-7ubuntu0.3, perl-base 5.40.1-7ubuntu0.3, and perl-modules-5.40 5.40.1-7ubuntu0.3.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 26.04 LTS (Resolute Raccoon)

Version: 5.40.1-7ubuntu0.3

Vendor release date: Sep 9, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 10, 2026

Description: Server operating system for Linux infrastructure and workloads.