USN-8684-1: Perl vulnerabilities
It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered that Perl incorrectly handled regular expressions with a large number of alternation branches. An attacker could possibly use this issue to cause incorrect matching results. (CVE-2026-13221) It was discovered that Perl incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-57433, CVE-2025-15649, CVE-2026-48959, CVE-2026-9538) It was discovered that Perl incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-48962) It was discovered that Perl incorrectly handled credential headers during cross-origin redirects in HTTP::Tiny. An attacker could possibly use this issue to expose sensitive information. (CVE-2026-7017)
CSIRTS triage
- What
- Multiple vulnerabilities including unsafe handling of Socket/pack functions leading to memory disclosure, regex matching errors, denial-of-service issues in file handling, and arbitrary code execution.
- Who is affected
- Systems running Perl with the affected functions in use, impacting a broad set of deployments.
- Urgency
- Multiple severity levels across the CVEs; RCE capability (CVE-2026-48962) requires immediate attention.
- Action
- Apply the Ubuntu security update USN-8684-1 or equivalent patches for your Perl installation.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Perl
Get an email when a new Perl advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8684-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-120870.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-574320.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-132210.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-574330.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-156490.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489590.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-95380.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489620.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-70170.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12087 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57432 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13221 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57433 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-15649 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48959 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9538 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48962 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7017 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] Perl: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Red Hat Enterprise Linux (perl-Archive-Tar, httplib2): Mehrere Schwachstellen ermöglichen De…cert-bund
- unknownUSN-8675-2: Perl vulnerabilitiesubuntu
- high[NEW] [high] IBM AIX and VIOS: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Red Hat Enterprise Linux (perl-IO-Compress): Vulnerability allows executing arbitrary progra…cert-bund
- unknownUSN-8675-1: Perl vulnerabilitiesubuntu
- unknownNCSC-2026-0321 [1.00] [M/H] Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOSncsc-nl
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- criticalCVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a cra…msrc
- mediumCVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alt…msrc
- highCVE-2026-57432: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-o…msrc
- criticalCVE-2026-57433: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a cra…nvd
More from Ubuntu Security Notices
- unknownUSN-8747-1: Beets vulnerability2026-09-10
- unknownUSN-8746-1: libEBML vulnerability2026-09-10
- unknownUSN-8745-1: KissFFT vulnerabilities2026-09-10
- unknownUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities2026-09-10
- unknownUSN-8744-1: Python vulnerabilities2026-09-10