{"id":"DEBIAN-CVE-2026-64193","details":"Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR.  Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt-\u003eedns-\u003eoption('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`\"\u003ccommand\u003e\"`} in EXTRA-TEXT.","modified":"2026-09-14T17:03:27.396021448Z","published":"2026-07-20T19:17:30.047Z","upstream":["CVE-2026-64193"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-64193"}],"affected":[{"package":{"name":"libnet-dns-perl","ecosystem":"Debian:13","purl":"pkg:deb/debian/libnet-dns-perl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.56-0+deb13u1"}]}],"versions":["1.50-1","1.53-1","1.54-1","1.55-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-64193.json"}},{"package":{"name":"libnet-dns-perl","ecosystem":"Debian:14","purl":"pkg:deb/debian/libnet-dns-perl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.56-1"}]}],"versions":["1.50-1","1.53-1","1.54-1","1.55-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-64193.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}