Ubuntu Security Notices USN-8467-1 USN-8467-1: Perl vulnerabilities Publication date 24 June 2026 Overview Several security issues were fixed in Perl. Releases 20.04 LTS 18.04 LTS 16.04 LTS 14.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages perl - Practical Extraction and Report Language Details It was discovered that Perl's Archive::Tar module incorrectly handled symlink and hardlink targets during extraction. An attacker could use this issue to read or overwrite arbitrary files outside the extraction directory. ( CVE-2026-42496 ) It was discovered that Perl had a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. ( CVE-2026-8376 ) It was discovered that Perl's Archive::Tar module incorrectly handled symlink and hardlink targets during extraction. An attacker could use this issue to read or overwrite arbitrary files outside the extraction directory. ( CVE-2026-42496 ) It was discovered that Perl had a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. ( CVE-2026-8376 ) Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 20.04 LTS focal libperl-dev – 5.30.0-9ubuntu0.5+esm2 Ubuntu Pro Fix available with Ubuntu Pro . libperl5.30 – 5.30.0-9ubuntu0.5+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl – 5.30.0-9ubuntu0.5+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl-base – 5.30.0-9ubuntu0.5+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl-debug – 5.30.0-9ubuntu0.5+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl-doc – 5.30.0-9ubuntu0.5+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl-modules-5.30 – 5.30.0-9ubuntu0.5+esm2 Ubuntu Pro Fix available with Ubuntu Pro . 18.04 LTS bionic libperl-dev – 5.26.1-6ubuntu0.7+esm2 Ubuntu Pro Fix available with Ubuntu Pro . libperl5.26 – 5.26.1-6ubuntu0.7+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl – 5.26.1-6ubuntu0.7+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl-base – 5.26.1-6ubuntu0.7+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl-debug – 5.26.1-6ubuntu0.7+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl-doc – 5.26.1-6ubuntu0.7+esm2 Ubuntu Pro Fix available with Ubuntu Pro . perl-modules-5.26 – 5.26.1-6ubuntu0.7+esm2 Ubuntu Pro Fix available with Ubuntu Pro . 16.04 LTS xenial libperl-dev – 5.22.1-9ubuntu0.9+esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. libperl5.22 – 5.22.1-9ubuntu0.9+esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. perl – 5.22.1-9ubuntu0.9+esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. perl-base – 5.22.1-9ubuntu0.9+esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. perl-debug – 5.22.1-9ubuntu0.9+esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. perl-doc – 5.22.1-9ubuntu0.9+esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. perl-modules-5.22 – 5.22.1-9ubuntu0.9+esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. 14.04 LTS trusty libperl-dev – 5.18.2-2ubuntu1.7+esm7 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. perl – 5.18.2-2ubuntu1.7+esm7 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. perl-base – 5.18.2-2ubuntu1.7+esm7 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. perl-debug – 5.18.2-2ubuntu1.7+esm7 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-8376 CVE-2026-8376
A critical vulnerability (CVE-2026-42496, CVSS 9.1) in Perl's Archive::Tar module allows arbitrary file read/write outside the extraction directory via mishandled symlink/hardlink targets, affecting archive-tar versions prior to 3.08. A separate critical heap buffer overflow (CVE-2026-8376, CVSS 9.8) exists in Perl when compiling certain regular expressions on 32-bit builds, potentially leading to denial of service or code execution, affecting Perl versions up to and including 5.43.10. Patches are available via standard system updates for affected Ubuntu LTS releases, requiring updates to specific package versions as listed in the USN.