{"id":"USN-8736-2","summary":"perl vulnerabilities","details":"USN-8736-1 fixed vulnerabilities in Perl. This update provides the\ncorresponding fix for Perl on Ubuntu 24.04 LTS.\n\nOriginal advisory details:\n\nIt was discovered that Perl incorrectly handled certain large inputs during\nregular expression matching. An attacker could possibly use this issue to\ntrigger out-of-bounds heap reads or writes, resulting in a denial of\nservice or arbitrary code execution. (CVE-2026-15534)\n\nIt was discovered that Perl incorrectly handled certain regular expression\ncontaining alternative matching branches. An attacker could  possibly use\nthis issue to cause incorrect regular expression matches, resulting in\nsecurity restrictions being bypassed. (CVE-2026-19487)","modified":"2026-09-17T02:57:28.244466132Z","published":"2026-09-16T14:37:44Z","related":["UBUNTU-CVE-2026-15534","UBUNTU-CVE-2026-19487"],"upstream":["CVE-2026-15534","CVE-2026-19487","UBUNTU-CVE-2026-15534","UBUNTU-CVE-2026-19487"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8736-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-15534"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-19487"}],"affected":[{"package":{"name":"perl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/perl?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.38.2-3.2ubuntu0.6"}]}],"versions":["5.36.0-9ubuntu1","5.36.0-10ubuntu1","5.38.2-3","5.38.2-3.2","5.38.2-3.2build1","5.38.2-3.2build2","5.38.2-3.2build2.1","5.38.2-3.2ubuntu0.1","5.38.2-3.2ubuntu0.2","5.38.2-3.2ubuntu0.3","5.38.2-3.2ubuntu0.4"],"ecosystem_specific":{"binaries":[{"binary_version":"5.38.2-3.2ubuntu0.6","binary_name":"libperl5.38t64"},{"binary_name":"perl","binary_version":"5.38.2-3.2ubuntu0.6"},{"binary_name":"perl-base","binary_version":"5.38.2-3.2ubuntu0.6"},{"binary_name":"perl-debug","binary_version":"5.38.2-3.2ubuntu0.6"},{"binary_name":"perl-modules-5.38","binary_version":"5.38.2-3.2ubuntu0.6"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:24.04:LTS","cves":[{"id":"CVE-2026-15534","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-19487","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8736-2.json"}}],"schema_version":"1.9.0"}