🛡️ OESA-2026-2844 — perl
Description
perl security update
Perl 5 is a highly capable, feature-rich programming language with over 30 years of development. Perl 5 runs on over 100 platforms from portables to mainframes and is suitable for both rapid prototyping and large scale development projects.
Security Fix(es):
Socket versions before 2.041 for Perl have an out-of-bounds heap read.
In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.
Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.(CVE-2026-12087)
Affected software
OESA-2026-2844 is recorded against 1 package.
- perl (fixed in 5.38.0-13.oe2403sp1)
Timeline and source
Published on 6 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| perl | — | 5.38.0-13.oe2403sp1 |
References
Similar Threats
- Unknown ALSA-2026:48225
- Unknown ALSA-2026:30851
- Unknown ALSA-2026:8096
- Unknown ALPINE-CVE-2026-4176
- Unknown ALPINE-CVE-2026-4167
More OESA 2026 advisories
Browse all of OESA 2026 in the advisory index.
Exploit Protection
Are you running perl?
OESA-2026-2844 carries CVSS 9.5 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For OESA-2026-2844 →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.