Version in base suite: 5.40.1-6 Base version: perl_5.40.1-6 Target version: perl_5.40.1-6+deb13u1 Base file: /srv/ftp-master.debian.org/ftp/pool/main/p/perl/perl_5.40.1-6.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/p/perl/perl_5.40.1-6+deb13u1.dsc /srv/release.debian.org/tmp/GqHoliV6qo/perl-5.40.1/debian/patches/fixes/CVE-2025-15649.diff |binary perl-5.40.1/debian/changelog | 32 perl-5.40.1/debian/patches/debian/doc_info.diff | 2 perl-5.40.1/debian/patches/fixes/CVE-2025-15649-tests.diff | 69 + perl-5.40.1/debian/patches/fixes/CVE-2026-12087.diff | 156 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-13221.diff | 73 + perl-5.40.1/debian/patches/fixes/CVE-2026-19487.diff | 64 + perl-5.40.1/debian/patches/fixes/CVE-2026-42496-1.diff | 84 + perl-5.40.1/debian/patches/fixes/CVE-2026-42496-2.diff | 56 + perl-5.40.1/debian/patches/fixes/CVE-2026-48959.diff | 28 perl-5.40.1/debian/patches/fixes/CVE-2026-48961.diff | 26 perl-5.40.1/debian/patches/fixes/CVE-2026-48962.diff | 165 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-57432-1.diff | 51 + perl-5.40.1/debian/patches/fixes/CVE-2026-57432-2.diff | 33 perl-5.40.1/debian/patches/fixes/CVE-2026-57433.diff | 30 perl-5.40.1/debian/patches/fixes/CVE-2026-7010-tests.diff | 76 + perl-5.40.1/debian/patches/fixes/CVE-2026-7010.diff | 42 perl-5.40.1/debian/patches/fixes/CVE-2026-7017-1.diff | 234 +++++ perl-5.40.1/debian/patches/fixes/CVE-2026-7017-2.diff | 435 ++++++++++ perl-5.40.1/debian/patches/fixes/CVE-2026-7017-3.diff | 78 + perl-5.40.1/debian/patches/fixes/CVE-2026-7017-4.diff | 62 + perl-5.40.1/debian/patches/fixes/CVE-2026-7017-5.diff | 106 ++ perl-5.40.1/debian/patches/fixes/CVE-2026-8376-tests.diff | 57 + perl-5.40.1/debian/patches/fixes/CVE-2026-8376.diff | 43 perl-5.40.1/debian/patches/series | 22 perl-5.40.1/debian/source/include-binaries | 2 26 files changed, 2025 insertions(+), 1 deletion(-) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpsx2uu38k/perl_5.40.1-6.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpsx2uu38k/perl_5.40.1-6+deb13u1.dsc: no acceptable signature found diff -Nru perl-5.40.1/debian/changelog perl-5.40.1/debian/changelog --- perl-5.40.1/debian/changelog 2025-07-27 19:41:22.000000000 +0000 +++ perl-5.40.1/debian/changelog 2026-08-30 08:53:55.000000000 +0000 @@ -1,3 +1,35 @@ +perl (5.40.1-6+deb13u1) trixie; urgency=medium + + * [SECURITY] various upstream fixes: + + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects. + (Closes: #1141639) + + CVE-2026-42496: Archive::Tar symlink extraction. + (Closes: #1138860) + + CVE-2026-42497: Archive::Tar hardlink extraction. + (Closes: #1138859) + + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read. + (Closes: #1140152) + + CVE-2026-13221: silently incorrect regular expression matches. + (Closes: #1142037) + + CVE-2025-15649: header parsing in IO::Uncompress::Unzip. + (Closes: #1138863) + + CVE-2026-7010: CRLF-validation in HTTP::Tiny. + (Closes: #1138858) + + CVE-2026-8376: Buffer overflow in Perl_study_chunk. + (Closes: #1137345) + + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip. + (Closes: #1138856) + + CVE-2026-48961: crash in zipdetails. + (Closes: #1138855) + + CVE-2026-48962: code execution in IO-Compress via output globs. + (Closes: #1138854) + + CVE-2026-57432: out of bound heap reads in pack() and unpack(). + (Closes: #1138905) + + CVE-2026-57433: signed integer overflow in Storable. + (Closes: #1138906) + + -- Niko Tyni Sun, 30 Aug 2026 11:53:55 +0300 + perl (5.40.1-6) unstable; urgency=medium * Update cross support files for the CVE-2025-40909 fix. diff -Nru perl-5.40.1/debian/patches/debian/doc_info.diff perl-5.40.1/debian/patches/debian/doc_info.diff --- perl-5.40.1/debian/patches/debian/doc_info.diff 2025-07-03 16:14:08.000000000 +0000 +++ perl-5.40.1/debian/patches/debian/doc_info.diff 2026-08-30 08:53:55.000000000 +0000 @@ -9,7 +9,7 @@ 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/pod/perl.pod b/pod/perl.pod -index 506d8f7..e149486 100644 +index 506d8f7..e1494868 100644 --- a/pod/perl.pod +++ b/pod/perl.pod @@ -319,8 +319,16 @@ aux h2ph h2xs perlbug pl2pm pod2html pod2man splain xsubpp diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2025-15649-tests.diff perl-5.40.1/debian/patches/fixes/CVE-2025-15649-tests.diff --- perl-5.40.1/debian/patches/fixes/CVE-2025-15649-tests.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2025-15649-tests.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,69 @@ +From: pmqs +Date: Sat, 25 Oct 2025 19:52:01 +0100 +Subject: Add tests for handling zero and invalid datetime values in unzip + functionality. Fix for #65 + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/pmqs/IO-Compress/commit/739698a7b1bb6814d1aa3c4a1b81374b16a9fea5 +Bug: https://github.com/pmqs/IO-Compress/issues/65 +Bug-Debian: https://bugs.debian.org/1138863 +--- + cpan/IO-Compress/t/006zip.t | 40 +++++++++++++++++++++++++++++++++++++++- + 1 file changed, 39 insertions(+), 1 deletion(-) + +diff --git a/cpan/IO-Compress/t/006zip.t b/cpan/IO-Compress/t/006zip.t +index 580d950..f975e36 100644 +--- a/cpan/IO-Compress/t/006zip.t ++++ b/cpan/IO-Compress/t/006zip.t +@@ -19,7 +19,7 @@ BEGIN { + $extra = 1 + if eval { require Test::NoWarnings ; Test::NoWarnings->import; 1 }; + +- plan tests => 108 + $extra ; ++ plan tests => 115 + $extra ; + + use_ok('IO::Compress::Zip', qw(:all)) ; + use_ok('IO::Uncompress::Unzip', qw(unzip $UnzipError)) ; +@@ -402,3 +402,41 @@ EOM + + is $line, qq["key","value"\n], "got line 1 from second member"; + } ++ ++ ++{ ++ title "bad datetime"; ++ # https://github.com/pmqs/IO-Compress/issues/65 ++ ++ { ++ # files/time-zero.zip has the modification time set to zero ++ my $file1 = "t/files/time-zero.zip"; ++ my $u = IO::Uncompress::Unzip->new( $file1) ++ or die "Cannot open $file1: $UnzipError"; ++ ++ isa_ok $u, "IO::Uncompress::Unzip"; ++ ++ my $name = $u->getHeaderInfo()->{Name}; ++ ++ my $hdr = $u->getHeaderInfo(); ++ is $hdr->{Name}, 'hello.txt', "Name is 'hello.txt'"; ++ is $hdr->{Time}, 0, "Time is zero"; ++ } ++ ++ ++ { ++ # files/time-invalid.zip has the modification time set to an invalid date ++ my $file1 = "t/files/time-invalid.zip"; ++ my $u = IO::Uncompress::Unzip->new( $file1) ++ or die "Cannot open $file1: $UnzipError"; ++ ++ isa_ok $u, "IO::Uncompress::Unzip"; ++ ++ my $name = $u->getHeaderInfo()->{Name}; ++ ++ my $hdr = $u->getHeaderInfo(); ++ is $hdr->{Name}, 'hello.txt', "Name is 'hello.txt'"; ++ is $hdr->{Time}, 0, "Time is zero"; ++ } ++ ++} Binary files /srv/release.debian.org/tmp/B4BsDx_C7b/perl-5.40.1/debian/patches/fixes/CVE-2025-15649.diff and /srv/release.debian.org/tmp/GqHoliV6qo/perl-5.40.1/debian/patches/fixes/CVE-2025-15649.diff differ diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-12087.diff perl-5.40.1/debian/patches/fixes/CVE-2026-12087.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-12087.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-12087.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,156 @@ +From: Paul "LeoNerd" Evans +Date: Mon, 4 May 2026 16:12:49 +0100 +Subject: cpan/Socket - Update to version 2.041 + +2.041 2026-03-26 + [CHANGES] + * Modernise Pod documentation formatting + + [BUGFIXES] + * Fix reuse of `STRLEN len` variable in pack_ip_mreq_source() + +(Backported to Debian 5.40 by Niko Tyni,including removal of the $VERSION increment) + +Origin: backport, https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb +Bug-Debian: https://bugs.debian.org/1140152 +--- + cpan/Socket/Socket.xs | 83 ++++++++++++++++++++++++++++++++++----------------- + 1 file changed, 56 insertions(+), 27 deletions(-) + +diff --git a/cpan/Socket/Socket.xs b/cpan/Socket/Socket.xs +index 1bd52a1..ded347e 100644 +--- a/cpan/Socket/Socket.xs ++++ b/cpan/Socket/Socket.xs +@@ -1272,26 +1272,35 @@ pack_ip_mreq(multiaddr, interface=&PL_sv_undef) + struct ip_mreq mreq; + char * multiaddrbytes; + char * interfacebytes; +- STRLEN len; +- if (DO_UTF8(multiaddr) && !sv_utf8_downgrade(multiaddr, 1)) +- croak("Wide character in %s", "Socket::pack_ip_mreq"); +- multiaddrbytes = SvPVbyte(multiaddr, len); +- if (len != sizeof(mreq.imr_multiaddr)) +- croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, +- "Socket::pack_ip_mreq", (UV)len, (UV)sizeof(mreq.imr_multiaddr)); ++ ++ { ++ if (DO_UTF8(multiaddr) && !sv_utf8_downgrade(multiaddr, 1)) ++ croak("Wide character in %s", "Socket::pack_ip_mreq"); ++ ++ STRLEN len; ++ multiaddrbytes = SvPVbyte(multiaddr, len); ++ if (len != sizeof(mreq.imr_multiaddr)) ++ croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, ++ "Socket::pack_ip_mreq", (UV)len, (UV)sizeof(mreq.imr_multiaddr)); ++ } ++ + Zero(&mreq, sizeof(mreq), char); + Copy(multiaddrbytes, &mreq.imr_multiaddr, sizeof(mreq.imr_multiaddr), char); + if(SvOK(interface)) { + if (DO_UTF8(interface) && !sv_utf8_downgrade(interface, 1)) + croak("Wide character in %s", "Socket::pack_ip_mreq"); ++ ++ STRLEN len; + interfacebytes = SvPVbyte(interface, len); + if (len != sizeof(mreq.imr_interface)) + croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, + "Socket::pack_ip_mreq", (UV)len, (UV)sizeof(mreq.imr_interface)); ++ + Copy(interfacebytes, &mreq.imr_interface, sizeof(mreq.imr_interface), char); + } + else + mreq.imr_interface.s_addr = INADDR_ANY; ++ + ST(0) = sv_2mortal(newSVpvn((char *)&mreq, sizeof(mreq))); + #else + not_here("pack_ip_mreq"); +@@ -1331,25 +1340,38 @@ pack_ip_mreq_source(multiaddr, source, interface=&PL_sv_undef) + char * multiaddrbytes; + char * sourcebytes; + char * interfacebytes; +- STRLEN len; +- if (DO_UTF8(multiaddr) && !sv_utf8_downgrade(multiaddr, 1)) +- croak("Wide character in %s", "Socket::pack_ip_mreq_source"); +- multiaddrbytes = SvPVbyte(multiaddr, len); +- if (len != sizeof(mreq.imr_multiaddr)) +- croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, +- "Socket::pack_ip_mreq", (UV)len, (UV)sizeof(mreq.imr_multiaddr)); +- if (DO_UTF8(source) && !sv_utf8_downgrade(source, 1)) +- croak("Wide character in %s", "Socket::pack_ip_mreq_source"); +- if (len != sizeof(mreq.imr_sourceaddr)) +- croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, +- "Socket::pack_ip_mreq", (UV)len, (UV)sizeof(mreq.imr_sourceaddr)); +- sourcebytes = SvPVbyte(source, len); ++ ++ { ++ if (DO_UTF8(multiaddr) && !sv_utf8_downgrade(multiaddr, 1)) ++ croak("Wide character in %s", "Socket::pack_ip_mreq_source"); ++ ++ STRLEN len; ++ multiaddrbytes = SvPVbyte(multiaddr, len); ++ if (len != sizeof(mreq.imr_multiaddr)) ++ croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, ++ "Socket::pack_ip_mreq", (UV)len, (UV)sizeof(mreq.imr_multiaddr)); ++ } ++ ++ { ++ if (DO_UTF8(source) && !sv_utf8_downgrade(source, 1)) ++ croak("Wide character in %s", "Socket::pack_ip_mreq_source"); ++ ++ STRLEN len; ++ sourcebytes = SvPVbyte(source, len); ++ if (len != sizeof(mreq.imr_sourceaddr)) ++ croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, ++ "Socket::pack_ip_mreq", (UV)len, (UV)sizeof(mreq.imr_sourceaddr)); ++ } ++ + Zero(&mreq, sizeof(mreq), char); + Copy(multiaddrbytes, &mreq.imr_multiaddr, sizeof(mreq.imr_multiaddr), char); + Copy(sourcebytes, &mreq.imr_sourceaddr, sizeof(mreq.imr_sourceaddr), char); ++ + if(SvOK(interface)) { + if (DO_UTF8(interface) && !sv_utf8_downgrade(interface, 1)) + croak("Wide character in %s", "Socket::pack_ip_mreq"); ++ ++ STRLEN len; + interfacebytes = SvPVbyte(interface, len); + if (len != sizeof(mreq.imr_interface)) + croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, +@@ -1358,6 +1380,7 @@ pack_ip_mreq_source(multiaddr, source, interface=&PL_sv_undef) + } + else + mreq.imr_interface.s_addr = INADDR_ANY; ++ + ST(0) = sv_2mortal(newSVpvn((char *)&mreq, sizeof(mreq))); + #else + PERL_UNUSED_VAR(multiaddr); +@@ -1398,16 +1421,22 @@ pack_ipv6_mreq(multiaddr, ifindex) + #ifdef HAS_IPV6_MREQ + struct ipv6_mreq mreq; + char * multiaddrbytes; +- STRLEN len; +- if (DO_UTF8(multiaddr) && !sv_utf8_downgrade(multiaddr, 1)) +- croak("Wide character in %s", "Socket::pack_ipv6_mreq"); +- multiaddrbytes = SvPVbyte(multiaddr, len); +- if (len != sizeof(mreq.ipv6mr_multiaddr)) +- croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, +- "Socket::pack_ipv6_mreq", (UV)len, (UV)sizeof(mreq.ipv6mr_multiaddr)); ++ ++ { ++ if (DO_UTF8(multiaddr) && !sv_utf8_downgrade(multiaddr, 1)) ++ croak("Wide character in %s", "Socket::pack_ipv6_mreq"); ++ ++ STRLEN len; ++ multiaddrbytes = SvPVbyte(multiaddr, len); ++ if (len != sizeof(mreq.ipv6mr_multiaddr)) ++ croak("Bad arg length %s, length is %" UVuf ", should be %" UVuf, ++ "Socket::pack_ipv6_mreq", (UV)len, (UV)sizeof(mreq.ipv6mr_multiaddr)); ++ } ++ + Zero(&mreq, sizeof(mreq), char); + Copy(multiaddrbytes, &mreq.ipv6mr_multiaddr, sizeof(mreq.ipv6mr_multiaddr), char); + mreq.ipv6mr_interface = ifindex; ++ + ST(0) = sv_2mortal(newSVpvn((char *)&mreq, sizeof(mreq))); + #else + PERL_UNUSED_VAR(multiaddr); diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-13221.diff perl-5.40.1/debian/patches/fixes/CVE-2026-13221.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-13221.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-13221.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,73 @@ +From: Karl Williamson +Date: Tue, 21 Jul 2026 21:27:30 +0100 +Subject: regcomp_study: Don't create a trie that would overflow + +This addresses GH #23388 + +The design of the trie compiling code is to batch extra long tries into +smaller chunks that fit into whatever limitations there are. However, +this ticket shows that that isn't always being done. + +In this case, a bunch of branches that have TAIL operands can be +combined together, and the final TAIL is used. And the code requires +that the delta between the first branch and this final TAIL fit into a +16-bit field. That is the root cause of this bug. + +I'm not familiar enough with the trie construction code to easily +understand why the final tail needs to be used here. So this patch +simply doesn't optimize a sequence of branches into a trie that would +overflow. + +This could be revisited by someone who knows more about this than I, or +earlier in the development cycle. + +(cherry picked from commit 03f74bbbd3a68350d926ee93d56ee4808c28c4c7) + +Bug: https://github.com/Perl/perl5/issues/23388 +Bug-Debian: https://bugs.debian.org/1142037 +Origin: upstream, https://github.com/Perl/perl5/commit/620e07a26ebd9dc0a398bf14eb6a2105cebd2448 +--- + regcomp_study.c | 10 ++++++++++ + t/re/pat_advanced.t | 8 ++++++++ + 2 files changed, 18 insertions(+) + +diff --git a/regcomp_study.c b/regcomp_study.c +index 209f497..b9dc212 100644 +--- a/regcomp_study.c ++++ b/regcomp_study.c +@@ -1840,6 +1840,16 @@ Perl_study_chunk(pTHX_ + tail = regnext( tail ); + } + ++ /* The code below currently saves the difference from ++ * start to finish in a 16-bit field, causing ++ * GH #23388. This defeats the design of batching ++ * tries into chunks that each fit. khw thinks it is ++ * too late in the 5.44 cycle to relook at the design, ++ * so for now anyway, don't make a trie that would ++ * overflow */ ++ if (tail - startbranch >= U16_MAX) { ++ continue; ++ } + + DEBUG_TRIE_COMPILE_r({ + regprop(RExC_rx, RExC_mysv, tail, NULL, pRExC_state); +diff --git a/t/re/pat_advanced.t b/t/re/pat_advanced.t +index 4d62f62..28f869e 100644 +--- a/t/re/pat_advanced.t ++++ b/t/re/pat_advanced.t +@@ -2713,6 +2713,14 @@ EOF_DEBUG_OUT + $x =~ s/^[\x{0301}\x{030C}]+//; + } + ++ { # GH #23388 ++ fresh_perl_is(<<~'PROG', , "", {}, "Avoid trie overflow"); ++ my $x = join "|", "aaa".."mzz"; ++ my $y = join "|", "naa".."zzz"; ++ use re 'Debug'; ++ "fnord" =~ m/(?:$x)|(?:$y)/; ++ PROG ++ } + + # !!! NOTE that tests that aren't at all likely to crash perl should go + # a ways above, above these last ones. There's a comment there that, like diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-19487.diff perl-5.40.1/debian/patches/fixes/CVE-2026-19487.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-19487.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-19487.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,64 @@ +From: Yves Orton +Date: Fri, 7 Feb 2025 10:06:10 +0100 +Subject: regexec.c - Fix GH 22892 - AHO-CORASICK edge case issue + +In some circumstances the AHO-CORASICK logic wasn't matching properly +when there were two possibilities whose proper prefix matches a proper +suffix of a third possibilty, and one of those possibilities was shorter +than the other. + +This was because we were NOT resetting the 'failed' flag properly. +This bug must be rare because it took more than a decade for anyone +to notice. + +This patch fixes the problem by resetting the failed flag after a +successful transition. + +A good example of this problem is as follows: + + "ABCDE" =~ m/ABCF|BCDE|C/ + +This should match 'BCDE' and not 'C'. Because of the flag issue we were +matching 'C' instead. + +This fixes https://github.com/Perl/perl5/issues/22892 + +(Backported to Debian 5.40 by Niko Tyni) + +Origin: backport, https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb +Bug: https://github.com/Perl/perl5/issues/22892 +Bug-Debian: https://bugs.debian.org/1144668 +--- + regexec.c | 1 + + t/re/re_tests | 6 ++++++ + 2 files changed, 7 insertions(+) + +diff --git a/regexec.c b/regexec.c +index c169835..f1d0ff1 100644 +--- a/regexec.c ++++ b/regexec.c +@@ -3409,6 +3409,7 @@ S_find_byclass(pTHX_ regexp * prog, const regnode *c, char *s, + { + DEBUG_TRIE_EXECUTE_r( + Perl_re_printf( aTHX_ " - legal\n")); ++ failed = 0; + state = tmp; + break; + } +diff --git a/t/re/re_tests b/t/re/re_tests +index 9188319..3a6cc5e 100644 +--- a/t/re/re_tests ++++ b/t/re/re_tests +@@ -2164,6 +2164,12 @@ AB\s+\x{100} AB \x{100}X y - - + [^\W\S]* a y $& + [^\W\S]? a y $& + ++ABCF|BCDE|C ABCDEX y $& BCDE - # GH 22892 - AHO-CORASICK bug ++ABCF|BCDE|C ABCDX y $& C - # GH 22892 - AHO-CORASICK bug ++ABCF|BCDE|C(G) ABCDE y $& BCDE - # GH 22892 - AHO-CORASICK bug ++ABCF|BCDE|C[Gg] ABCDE y $& BCDE - # GH 22892 - AHO-CORASICK bug ++ABCF|BCD[Ee]|C[Gg] ABCDE y $& BCDE - # GH 22892 - AHO-CORASICK bug ++ + # Keep these lines at the end of the file + # pat string y/n/etc expr expected-expr skip-reason comment + # vim: softtabstop=0 noexpandtab diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-42496-1.diff perl-5.40.1/debian/patches/fixes/CVE-2026-42496-1.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-42496-1.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-42496-1.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,84 @@ +From: Stig Palmquist +Date: Thu, 21 May 2026 19:59:21 +0100 +Subject: Validate symlink and hardlink linkname in SECURE MODE + +Signed-off-by: Chris 'BinGOs' Williams + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158 +Bug-Debian: https://bugs.debian.org/1138859 +Bug-Debian: https://bugs.debian.org/1138860 +--- + cpan/Archive-Tar/lib/Archive/Tar.pm | 30 ++++++++++++++++++++++++++++++ + cpan/Archive-Tar/t/04_resolved_issues.t | 2 ++ + 2 files changed, 32 insertions(+) + +diff --git a/cpan/Archive-Tar/lib/Archive/Tar.pm b/cpan/Archive-Tar/lib/Archive/Tar.pm +index 665b04a..c658733 100644 +--- a/cpan/Archive-Tar/lib/Archive/Tar.pm ++++ b/cpan/Archive-Tar/lib/Archive/Tar.pm +@@ -954,6 +954,19 @@ sub _make_special_file { + my $err; + + if( $entry->is_symlink ) { ++ if( !$INSECURE_EXTRACT_MODE ) { ++ my $linkname = $entry->linkname; ++ if( File::Spec->file_name_is_absolute($linkname) ) { ++ $self->_error( qq[Symlink '] . $entry->full_path . ++ qq[' has absolute target. Not extracting under SECURE EXTRACT MODE] ); ++ return; ++ } ++ if( grep { $_ eq '..' } File::Spec->splitdir($linkname) ) { ++ $self->_error( qq[Symlink '] . $entry->full_path . ++ qq[' target attempts traversal. Not extracting under SECURE EXTRACT MODE] ); ++ return; ++ } ++ } + my $fail; + if( ON_UNIX ) { + symlink( $entry->linkname, $file ) or $fail++; +@@ -967,6 +980,23 @@ sub _make_special_file { + $entry->linkname .q[' failed] if $fail; + + } elsif ( $entry->is_hardlink ) { ++ if( !$INSECURE_EXTRACT_MODE ) { ++ my $linkname = $entry->linkname; ++ if( File::Spec->file_name_is_absolute($linkname) ) { ++ $self->_error( qq[Hardlink '] . $entry->full_path . ++ qq[' has absolute target '$linkname'. Not extracting ] . ++ qq[under SECURE EXTRACT MODE: extraction itself chmods ] . ++ qq[the shared inode.] ); ++ return; ++ } ++ if( grep { $_ eq '..' } File::Spec->splitdir($linkname) ) { ++ $self->_error( qq[Hardlink '] . $entry->full_path . ++ qq[' target '$linkname' attempts traversal. Not ] . ++ qq[extracting under SECURE EXTRACT MODE: extraction ] . ++ qq[itself chmods the shared inode.] ); ++ return; ++ } ++ } + my $fail; + if( ON_UNIX ) { + link( $entry->linkname, $file ) or $fail++; +diff --git a/cpan/Archive-Tar/t/04_resolved_issues.t b/cpan/Archive-Tar/t/04_resolved_issues.t +index b7e7860..7e64a07 100644 +--- a/cpan/Archive-Tar/t/04_resolved_issues.t ++++ b/cpan/Archive-Tar/t/04_resolved_issues.t +@@ -220,6 +220,7 @@ if ($^O ne 'msys') # symlink tests fail on Windows/msys2 + } + + { #use case 1 - in memory extraction ++ local $Archive::Tar::INSECURE_EXTRACT_MODE=1; + my $t=Archive::Tar->new; + $t->read( $archname ); + my $r = eval{ $t->extract }; +@@ -231,6 +232,7 @@ if ($^O ne 'msys') # symlink tests fail on Windows/msys2 + + { #use case 2 - iter extraction + #$DB::single = 2; ++ local $Archive::Tar::INSECURE_EXTRACT_MODE=1; + my $next=Archive::Tar->iter( $archname, 1 ); + my $failed = 0; + #use Data::Dumper; diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-42496-2.diff perl-5.40.1/debian/patches/fixes/CVE-2026-42496-2.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-42496-2.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-42496-2.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,56 @@ +From: Stig Palmquist +Date: Tue, 2 Jun 2026 16:09:03 +0200 +Subject: Allow `..` links in secure extract in parent path + +Assisted-by: OpenAI Codex +Signed-off-by: Stig Palmquist + +(Backported for Debian by Niko Tyni, fixes a regression with the earlier change) + +Origin: backport, https://github.com/jib/archive-tar-new/commit/484f71ea0189ed46690f50dc7ee71d4b8bc0e70f +Bug: https://github.com/jib/archive-tar-new/pull/48 +Bug-Debian: https://bugs.debian.org/1138859 +Bug-Debian: https://bugs.debian.org/1138860 +--- + cpan/Archive-Tar/lib/Archive/Tar.pm | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/cpan/Archive-Tar/lib/Archive/Tar.pm b/cpan/Archive-Tar/lib/Archive/Tar.pm +index c658733..157a5d6 100644 +--- a/cpan/Archive-Tar/lib/Archive/Tar.pm ++++ b/cpan/Archive-Tar/lib/Archive/Tar.pm +@@ -961,7 +961,7 @@ sub _make_special_file { + qq[' has absolute target. Not extracting under SECURE EXTRACT MODE] ); + return; + } +- if( grep { $_ eq '..' } File::Spec->splitdir($linkname) ) { ++ if( !defined _symlinks_resolver( $entry->full_path, $linkname, 1 ) ) { + $self->_error( qq[Symlink '] . $entry->full_path . + qq[' target attempts traversal. Not extracting under SECURE EXTRACT MODE] ); + return; +@@ -989,7 +989,7 @@ sub _make_special_file { + qq[the shared inode.] ); + return; + } +- if( grep { $_ eq '..' } File::Spec->splitdir($linkname) ) { ++ if( !defined _symlinks_resolver( $entry->full_path, $linkname, 1 ) ) { + $self->_error( qq[Hardlink '] . $entry->full_path . + qq[' target '$linkname' attempts traversal. Not ] . + qq[extracting under SECURE EXTRACT MODE: extraction ] . +@@ -2014,7 +2014,7 @@ sub no_string_support { + } + + sub _symlinks_resolver{ +- my ($src, $trg) = @_; ++ my ($src, $trg, $strict) = @_; + my @src = split /[\/\\]/, $src; + my @trg = split /[\/\\]/, $trg; + pop @src; #strip out current object name +@@ -2027,6 +2027,7 @@ sub _symlinks_resolver{ + next if $part eq '.'; #ignore current + if($part eq '..'){ + #got to parent ++ return if $strict && !@src; + pop @src; + } + else{ diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-48959.diff perl-5.40.1/debian/patches/fixes/CVE-2026-48959.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-48959.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-48959.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,28 @@ +From: pmqs +Date: Fri, 15 May 2026 23:18:39 +0100 +Subject: Fix typo in fastForward #72 + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2 +Bug: https://github.com/pmqs/IO-Compress/issues/72 +Bug-Debian: https://bugs.debian.org/1138856 +--- + cpan/IO-Compress/lib/IO/Uncompress/Unzip.pm | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/cpan/IO-Compress/lib/IO/Uncompress/Unzip.pm b/cpan/IO-Compress/lib/IO/Uncompress/Unzip.pm +index 802ee3c..65befa8 100644 +--- a/cpan/IO-Compress/lib/IO/Uncompress/Unzip.pm ++++ b/cpan/IO-Compress/lib/IO/Uncompress/Unzip.pm +@@ -157,8 +157,8 @@ sub fastForward + + while ($offset > 0) + { +- $c = length $offset +- if length $offset < $c ; ++ $c = $offset ++ if $offset < $c ; + + $offset -= $c; + diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-48961.diff perl-5.40.1/debian/patches/fixes/CVE-2026-48961.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-48961.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-48961.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,26 @@ +From: Jah-yee <166608075+Jah-yee@users.noreply.github.com> +Date: Sun, 8 Mar 2026 14:53:15 +0000 +Subject: fix: correct unpackValueQ -> unpackValue_Q typo in decodeLitteEndian + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/pmqs/zipdetails/commit/42da886f43ebd2a8c613ad431208b8df20c9cc22 +Bug: https://github.com/pmqs/zipdetails/pull/32 +Bug-Debian: https://bugs.debian.org/1138855 +--- + cpan/IO-Compress/bin/zipdetails | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/cpan/IO-Compress/bin/zipdetails b/cpan/IO-Compress/bin/zipdetails +index 7dd1f55..9564bab 100644 +--- a/cpan/IO-Compress/bin/zipdetails ++++ b/cpan/IO-Compress/bin/zipdetails +@@ -4981,7 +4981,7 @@ sub decodeLitteEndian + + if (length $value == 8) + { +- return unpackValueQ ($value) ++ return unpackValue_Q ($value) + } + elsif (length $value == 4) + { diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-48962.diff perl-5.40.1/debian/patches/fixes/CVE-2026-48962.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-48962.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-48962.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,165 @@ +From: pmqs +Date: Sat, 16 May 2026 17:48:34 +0100 +Subject: remove use of eval in globmapper. #73 + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610 +Bug: https://github.com/pmqs/IO-Compress/issues/73 +Bug-Debian: https://bugs.debian.org/1138854 +--- + cpan/IO-Compress/lib/File/GlobMapper.pm | 52 +++++++++++++++++++++++++++------ + cpan/IO-Compress/t/globmapper.t | 52 ++++++++++++++++++++++++++++++++- + 2 files changed, 94 insertions(+), 10 deletions(-) + +diff --git a/cpan/IO-Compress/lib/File/GlobMapper.pm b/cpan/IO-Compress/lib/File/GlobMapper.pm +index 53f957a..6454bc4 100644 +--- a/cpan/IO-Compress/lib/File/GlobMapper.pm ++++ b/cpan/IO-Compress/lib/File/GlobMapper.pm +@@ -29,6 +29,11 @@ our ($VERSION, @EXPORT_OK); + $VERSION = '1.001'; + @EXPORT_OK = qw( globmap ); + ++our $BEGIN_DELIM = "\xFF"; ++our $END_DELIM = "\xFE"; ++our $BACKSLASH_ESC = "\xFD"; ++our $HASH_ESC = "\xFC"; ++our $STAR_ESC = "\xFB"; + + our ($noPreBS, $metachars, $matchMetaRE, %mapping, %wildCount); + $noPreBS = '(?{InputPattern}'\n"; ++ # print "OUTPUT '$self->{OutputGlob}' => '$string'\n"; + +- #print "OUTPUT '$self->{OutputGlob}' => '$string'\n"; + $self->{OutputPattern} = $string ; + + return 1 ; +@@ -335,11 +349,31 @@ sub _getFiles + next if $inFiles{$inFile} ++ ; + + my $outFile = $inFile ; ++ my @matches ; ++ ++ my $noPreESC = '(?{InputPattern}/ ) ++ if (@matches = ($inFile =~ m/$self->{InputPattern}/ )) + { +- no warnings 'uninitialized'; +- eval "\$outFile = $self->{OutputPattern};" ; ++ $outFile = $self->{OutputPattern}; ++ my $ix = 1; ++ ++ # get the filename glob ++ $outFile =~ s/${noPreESC}${BEGIN_DELIM}${END_DELIM}/$inFile/g; ++ ++ # now each of the #1, #2,... ++ for my $pattern (@matches) ++ { ++ $outFile =~ s/${noPreESC}${BEGIN_DELIM}${ix}${END_DELIM}/$pattern/g; ++ ++ ++ $ix; ++ } ++ ++ # unescape ++ $outFile =~ s/${BEGIN_DELIM}${BEGIN_DELIM}/${BEGIN_DELIM}/g; ++ $outFile =~ s/${END_DELIM}${END_DELIM}/${END_DELIM}/g; ++ $outFile =~ s/${HASH_ESC}/#/g; ++ $outFile =~ s/${STAR_ESC}/*/g; + + if (defined $outInMapping{$outFile}) + { +diff --git a/cpan/IO-Compress/t/globmapper.t b/cpan/IO-Compress/t/globmapper.t +index 75fa768..842562f 100644 +--- a/cpan/IO-Compress/t/globmapper.t ++++ b/cpan/IO-Compress/t/globmapper.t +@@ -24,7 +24,7 @@ Perl $]" ) + $extra = 1 + if eval { require Test::NoWarnings ; Test::NoWarnings->import; 1 }; + +- plan tests => 68 + $extra ; ++ plan tests => 76 + $extra ; + + use_ok('File::GlobMapper') ; + } +@@ -290,6 +290,56 @@ Perl $]" ) + ], " got mapping"; + } + ++{ ++ title "check escaping"; ++ ++ my $tmpDir ;#= 'td'; ++ my $lex = LexDir->new( $tmpDir ); ++ ++ my $BEGIN_DELIM = "\xFF"; ++ my $END_DELIM = "\xFE"; ++ ++ #mkdir $tmpDir, 0777 ; ++ ++ touch map { "$tmpDir/$_.tmp" } qw( abc1 abc2 abc3 ) ; ++ ++ my $map = File::GlobMapper::globmap("$tmpDir/*b*.tmp", "$tmpDir/X-${BEGIN_DELIM}#2-#1${END_DELIM}-X"); ++ ok $map, " got map" ++ or diag $File::GlobMapper::Error ; ++ ++ is @{ $map }, 3, " returned 3 maps"; ++ is_deeply $map, ++ [ [map { "$tmpDir/$_" } ("abc1.tmp", "X-${BEGIN_DELIM}c1-a${END_DELIM}-X")], ++ [map { "$tmpDir/$_" } ("abc2.tmp", "X-${BEGIN_DELIM}c2-a${END_DELIM}-X")], ++ [map { "$tmpDir/$_" } ("abc3.tmp", "X-${BEGIN_DELIM}c3-a${END_DELIM}-X")], ++ ], " got mapping"; ++} ++ ++{ ++ title "check backslash escaping"; ++ ++ my $tmpDir ;#= 'td'; ++ my $lex = LexDir->new( $tmpDir ); ++ ++ my $BEGIN_DELIM = "\xFF"; ++ my $END_DELIM = "\xFE"; ++ ++ #mkdir $tmpDir, 0777 ; ++ ++ touch map { "$tmpDir/$_.tmp" } qw( abc1 abc2 abc3 ) ; ++ ++ my $map = File::GlobMapper::globmap("$tmpDir/*b*.tmp", $tmpDir . '/X-#2-\\#1\\*-X'); ++ ok $map, " got map" ++ or diag $File::GlobMapper::Error ; ++ ++ is @{ $map }, 3, " returned 3 maps"; ++ is_deeply $map, ++ [ [map { "$tmpDir/$_" } ("abc1.tmp", "X-c1-#1*-X")], ++ [map { "$tmpDir/$_" } ("abc2.tmp", "X-c2-#1*-X")], ++ [map { "$tmpDir/$_" } ("abc3.tmp", "X-c3-#1*-X")], ++ ], " got mapping"; ++} ++ + # TODO + # test each of the wildcard metacharacters can be mapped to the output filename + # diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-57432-1.diff perl-5.40.1/debian/patches/fixes/CVE-2026-57432-1.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-57432-1.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-57432-1.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,51 @@ +From: Paul "LeoNerd" Evans +Date: Sat, 9 May 2026 17:18:43 +0100 +Subject: pp_pack.c: Avoid ssize_t overflow when calculating the size of a + structure + +If the user has requested a size that would overflow a SSize_t, then the +only sensible thing to do is throw an exception, because the structure +this implies couldn't possibly fit into memory anyway. + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 +Bug: https://github.com/Perl/perl5/issues/24445 +Bug-Debian: https://bugs.debian.org/1138905 +--- + pod/perldiag.pod | 6 ++++++ + pp_pack.c | 4 ++++ + 2 files changed, 10 insertions(+) + +diff --git a/pod/perldiag.pod b/pod/perldiag.pod +index dafd655..d308a94 100644 +--- a/pod/perldiag.pod ++++ b/pod/perldiag.pod +@@ -4995,6 +4995,12 @@ mixed-case attribute name, instead. See L. + (F) You can't specify a repeat count so large that it overflows your + signed integers. See L. + ++=item Pack template structure size is too large ++ ++(F) You called C or C to operate on a structure, whose ++computed size is too large to fit in memory. This usually happens as a ++result of embedding a large number as the repeat count for an item. ++ + =item page overflow + + (W io) A single call to write() produced more lines than can fit on a +diff --git a/pp_pack.c b/pp_pack.c +index f436b45..3ef78a8 100644 +--- a/pp_pack.c ++++ b/pp_pack.c +@@ -528,6 +528,10 @@ S_measure_struct(pTHX_ tempsym_t* symptr) + break; + } + } ++ if ((size > 0) && ++ ((len > SSize_t_MAX / size) || /* detect overflow of len * size */ ++ (len * size > SSize_t_MAX - total))) /* detect overflow of total + len * size */ ++ croak("Pack template structure size is too large"); + total += len * size; + } + return total; diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-57432-2.diff perl-5.40.1/debian/patches/fixes/CVE-2026-57432-2.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-57432-2.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-57432-2.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,33 @@ +From: Paul "LeoNerd" Evans +Date: Mon, 11 May 2026 12:25:33 +0100 +Subject: pp_pack.c: Avoid some other potential overflows when calculating + sizes + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e +Bug: https://github.com/Perl/perl5/issues/24445 +Bug-Debian: https://bugs.debian.org/1138905 +--- + pp_pack.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/pp_pack.c b/pp_pack.c +index 3ef78a8..37e90ab 100644 +--- a/pp_pack.c ++++ b/pp_pack.c +@@ -513,12 +513,12 @@ S_measure_struct(pTHX_ tempsym_t* symptr) + break; + case 'B': + case 'b': +- len = (len + 7)/8; ++ len = (len / 8) + !!(len % 8); + size = 1; + break; + case 'H': + case 'h': +- len = (len + 1)/2; ++ len = (len / 2) + !!(len % 2); + size = 1; + break; + diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-57433.diff perl-5.40.1/debian/patches/fixes/CVE-2026-57433.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-57433.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-57433.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,30 @@ +From: Paul "LeoNerd" Evans +Date: Sat, 9 May 2026 16:47:14 +0100 +Subject: Storable.xs: Avoid signed int overflow when unpacking a list of hook + data items + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7 +Bug: https://github.com/Perl/perl5/pull/24413 +Bug-Debian: https://bugs.debian.org/1138906 +--- + dist/Storable/Storable.xs | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/dist/Storable/Storable.xs b/dist/Storable/Storable.xs +index a558dd7..387b55f 100644 +--- a/dist/Storable/Storable.xs ++++ b/dist/Storable/Storable.xs +@@ -5037,7 +5037,10 @@ static SV *retrieve_hook_common(pTHX_ stcxt_t *cxt, const char *cname, int large + } + else + GETMARK(len3); +- if (len3) { ++ if (len3 == I32_MAX) ++ /* If len3 is exactly I32_MAX it will upset av_extend below */ ++ CROAK(("Invalid count of hook data items")); ++ else if (len3) { + av = newAV(); + av_extend(av, len3 + 1); /* Leave room for [0] */ + AvFILLp(av) = len3; /* About to be filled anyway */ diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-7010-tests.diff perl-5.40.1/debian/patches/fixes/CVE-2026-7010-tests.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-7010-tests.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-7010-tests.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,76 @@ +From: Stig Palmquist +Date: Mon, 27 Apr 2026 01:09:08 +0200 +Subject: CVE-2026-7010: add tests + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/207890b6dab21c9db314af50d63202d13f317e2a +Bug: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/34 +Bug-Debian: https://bugs.debian.org/1138858 +--- + cpan/HTTP-Tiny/t/020_headers.t | 55 ++++++++++++++++++++++++++++++++++++++++++ + 1 file changed, 55 insertions(+) + +diff --git a/cpan/HTTP-Tiny/t/020_headers.t b/cpan/HTTP-Tiny/t/020_headers.t +index a4254e5..665be23 100644 +--- a/cpan/HTTP-Tiny/t/020_headers.t ++++ b/cpan/HTTP-Tiny/t/020_headers.t +@@ -59,3 +59,58 @@ use HTTP::Tiny; + is_deeply($handle->read_header_lines, $headers, "roundtrip header lines"); + } + ++{ ++ my $fh = tmpfile(); ++ my $handle = HTTP::Tiny::Handle->new(fh => $fh); ++ eval { $handle->write_header_lines({ range => "bytes=13-37${CRLF}X-Injected: foo" }) }; ++ like($@, qr/Invalid HTTP header field value \(Range\)/, ++ "reject CRLF in control field value"); ++} ++ ++{ ++ my $fh = tmpfile(); ++ my $handle = HTTP::Tiny::Handle->new(fh => $fh); ++ eval { $handle->write_header_lines({ "X-Foo-Bar" => "foo${CRLF}X-Injected: foo" }) }; ++ like($@, qr/Invalid HTTP header field value \(X-Foo-Bar\)/, ++ "reject CRLF in other header value"); ++} ++ ++{ ++ my $fh = tmpfile(); ++ my $handle = HTTP::Tiny::Handle->new(fh => $fh); ++ eval { $handle->write_request_header("GET${CRLF}", "/foo", {}, {}) }; ++ like($@, qr/Invalid characters in Method/, ++ "->write_request_header() reject CRLF in method"); ++} ++ ++{ ++ my $fh = tmpfile(); ++ my $handle = HTTP::Tiny::Handle->new(fh => $fh); ++ eval { $handle->write_request_header("GET\x00", "/foo", {}, {}) }; ++ like($@, qr/Invalid characters in Method/, ++ "->write_request_header() reject nullbyte in method"); ++} ++ ++{ ++ my $fh = tmpfile(); ++ my $handle = HTTP::Tiny::Handle->new(fh => $fh); ++ eval { $handle->write_request_header("GET ", "/foo", {}, {}) }; ++ like($@, qr/Invalid characters in Method/, ++ "->write_request_header() reject trailing space in method"); ++} ++ ++{ ++ my $fh = tmpfile(); ++ my $handle = HTTP::Tiny::Handle->new(fh => $fh); ++ eval { $handle->write_request_header("GET", "/foo${CRLF}Foo: 1", {}, {}) }; ++ like($@, qr/Invalid characters in Request-URI/, ++ "->write_request_header() reject CRLF in request-uri"); ++} ++ ++{ ++ my $fh = tmpfile(); ++ my $handle = HTTP::Tiny::Handle->new(fh => $fh); ++ eval { $handle->write_request_header("GET", "/foo bar", {}, {}) }; ++ like($@, qr/Invalid characters in Request-URI/, ++ "->write_request_header() reject space in request-uri"); ++} diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-7010.diff perl-5.40.1/debian/patches/fixes/CVE-2026-7010.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-7010.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-7010.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,42 @@ +From: Stig +Date: Mon, 27 Apr 2026 00:57:48 +0200 +Subject: CVE-2026-7010: fix for request / header smuggling + +Validate control headers, request uri and request method for characters +that could be used in request smuggling or header injection attacks. + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d +Bug: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/34 +Bug-Debian: https://bugs.debian.org/1138858 +--- + cpan/HTTP-Tiny/lib/HTTP/Tiny.pm | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm b/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm +index b9832eb..1d328ae 100644 +--- a/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm ++++ b/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm +@@ -1377,6 +1377,8 @@ sub write_header_lines { + my $field_name = $HeaderCase{$k}; + my $v = $headers->{$k}; + for (ref $v eq 'ARRAY' ? @$v : $v) { ++ die(qq/Invalid HTTP header field value ($field_name): / . $Printable->($_). "\n") ++ unless $_ eq '' || /\A $Field_Content \z/xo; + $_ = '' unless defined $_; + $buf .= "$field_name: $_\x0D\x0A"; + } +@@ -1568,6 +1570,12 @@ sub write_request_header { + @_ == 5 || die(q/Usage: $handle->write_request_header(method, request_uri, headers, header_case)/ . "\n"); + my ($self, $method, $request_uri, $headers, $header_case) = @_; + ++ die (q/Invalid characters in Request-URI /. $Printable->($request_uri). "\n") ++ if $request_uri =~ /[\x00-\x20\x7F]/; ++ ++ die (q/Invalid characters in Method /. $Printable->($method). "\n") ++ if $method =~ /[\x00-\x20\x7F]/; ++ + return $self->write_header_lines($headers, $header_case, "$method $request_uri HTTP/1.1\x0D\x0A"); + } + diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-7017-1.diff perl-5.40.1/debian/patches/fixes/CVE-2026-7017-1.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-7017-1.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-7017-1.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,234 @@ +From: Olaf Alders +Date: Thu, 14 May 2026 00:13:01 +0000 +Subject: refuse https to http redirects by default + +Allow opt in via allow_downgrade + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3 +Bug: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36 +Bug-Debian: https://bugs.debian.org/1140152 +--- + cpan/HTTP-Tiny/corpus/redirect-11.txt | 21 ++++++++++++++++++++ + cpan/HTTP-Tiny/corpus/redirect-12.txt | 36 +++++++++++++++++++++++++++++++++++ + cpan/HTTP-Tiny/corpus/redirect-13.txt | 35 ++++++++++++++++++++++++++++++++++ + cpan/HTTP-Tiny/corpus/redirect-14.txt | 35 ++++++++++++++++++++++++++++++++++ + cpan/HTTP-Tiny/lib/HTTP/Tiny.pm | 14 ++++++++++++-- + cpan/HTTP-Tiny/t/001_api.t | 2 +- + 6 files changed, 140 insertions(+), 3 deletions(-) + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-11.txt + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-12.txt + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-13.txt + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-14.txt + +diff --git a/cpan/HTTP-Tiny/corpus/redirect-11.txt b/cpan/HTTP-Tiny/corpus/redirect-11.txt +new file mode 100644 +index 0000000..6ecdf4d +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-11.txt +@@ -0,0 +1,21 @@ ++url ++ https://victim.example/secret ++expected ++ refused-redirect-body ++expected_url ++ https://victim.example/secret ++---------- ++GET /secret HTTP/1.1 ++Host: victim.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 21 ++Location: http://victim.example/secret ++ ++refused-redirect-body ++ +diff --git a/cpan/HTTP-Tiny/corpus/redirect-12.txt b/cpan/HTTP-Tiny/corpus/redirect-12.txt +new file mode 100644 +index 0000000..8509b24 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-12.txt +@@ -0,0 +1,36 @@ ++url ++ https://victim.example/secret ++expected ++ success ++expected_url ++ http://victim.example/secret ++new_args ++ allow_downgrade: 1 ++---------- ++GET /secret HTTP/1.1 ++Host: victim.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: http://victim.example/secret ++ ++redirect ++ ++---------- ++GET /secret HTTP/1.1 ++Host: victim.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 7 ++ ++success +diff --git a/cpan/HTTP-Tiny/corpus/redirect-13.txt b/cpan/HTTP-Tiny/corpus/redirect-13.txt +new file mode 100644 +index 0000000..6d22dc9 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-13.txt +@@ -0,0 +1,35 @@ ++url ++ https://example.com/index.html ++expected ++ abcdefghijklmnopqrstuvwxyz1234567890abcdef ++expected_url ++ https://example.com/index2.html ++---------- ++GET /index.html HTTP/1.1 ++Host: example.com ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/html ++Content-Length: 53 ++Location: https://example.com/index2.html ++ ++redirect ++ ++---------- ++GET /index2.html HTTP/1.1 ++Host: example.com ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 42 ++ ++abcdefghijklmnopqrstuvwxyz1234567890abcdef ++ +diff --git a/cpan/HTTP-Tiny/corpus/redirect-14.txt b/cpan/HTTP-Tiny/corpus/redirect-14.txt +new file mode 100644 +index 0000000..31e81f3 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-14.txt +@@ -0,0 +1,35 @@ ++url ++ http://example.com/index.html ++expected ++ abcdefghijklmnopqrstuvwxyz1234567890abcdef ++expected_url ++ https://example.com/index2.html ++---------- ++GET /index.html HTTP/1.1 ++Host: example.com ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/html ++Content-Length: 53 ++Location: https://example.com/index2.html ++ ++redirect ++ ++---------- ++GET /index2.html HTTP/1.1 ++Host: example.com ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 42 ++ ++abcdefghijklmnopqrstuvwxyz1234567890abcdef ++ +diff --git a/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm b/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm +index 1d328ae..e4937cb 100644 +--- a/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm ++++ b/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm +@@ -18,6 +18,10 @@ sub _croak { require Carp; Carp::croak(@_) } + #pod * C — A user-agent string (defaults to 'HTTP-Tiny/$VERSION'). If + #pod C — ends in a space character, the default user-agent string is + #pod appended. ++#pod * C — If a 3xx redirect changes the scheme from C to ++#pod plain C, HTTP::Tiny will by default refuse to follow it, returning the ++#pod 3xx response. Set this to a true value to revert to the legacy behavior of ++#pod redirecting C to C. Default is C. + #pod * C — An instance of L — or equivalent class + #pod that supports the C and C methods + #pod * C — A hashref of default headers to apply to requests +@@ -72,8 +76,8 @@ sub _croak { require Carp; Carp::croak(@_) } + my @attributes; + BEGIN { + @attributes = qw( +- cookie_jar default_headers http_proxy https_proxy keep_alive +- local_address max_redirect max_size proxy no_proxy ++ allow_downgrade cookie_jar default_headers http_proxy https_proxy ++ keep_alive local_address max_redirect max_size proxy no_proxy + SSL_options verify_SSL + ); + my %persist_ok = map {; $_ => 1 } qw( +@@ -955,6 +959,11 @@ sub _maybe_redirect { + my $location = ($headers->{location} =~ /^\//) + ? "$request->{scheme}://$request->{host_port}$headers->{location}" + : $headers->{location} ; ++ my ($to_scheme) = $self->_split_url($location); ++ if (!$self->{allow_downgrade} && $request->{scheme} eq 'https' && $to_scheme eq 'http' ) { ++ return; ++ } ++ + return (($status eq '303' ? 'GET' : $method), $location); + } + return; +@@ -2069,6 +2078,7 @@ host has closed its end of the socket. + + =for Pod::Coverage SSL_options + agent ++allow_downgrade + cookie_jar + default_headers + http_proxy +diff --git a/cpan/HTTP-Tiny/t/001_api.t b/cpan/HTTP-Tiny/t/001_api.t +index 48cc2f8..7e1fa57 100644 +--- a/cpan/HTTP-Tiny/t/001_api.t ++++ b/cpan/HTTP-Tiny/t/001_api.t +@@ -7,7 +7,7 @@ use Test::More tests => 2; + use HTTP::Tiny; + + my @accessors = qw( +- agent default_headers http_proxy https_proxy keep_alive local_address ++ agent allow_downgrade default_headers http_proxy https_proxy keep_alive local_address + max_redirect max_size proxy no_proxy timeout SSL_options verify_SSL cookie_jar + ); + my @methods = qw( diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-7017-2.diff perl-5.40.1/debian/patches/fixes/CVE-2026-7017-2.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-7017-2.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-7017-2.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,435 @@ +From: Olaf Alders +Date: Thu, 14 May 2026 17:50:22 +0000 +Subject: strip auth headers on cross-origin redirects + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3 +Bug: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36 +Bug-Debian: https://bugs.debian.org/1140152 +--- + cpan/HTTP-Tiny/corpus/redirect-15.txt | 57 +++++++++++++++++++++++++++++++++++ + cpan/HTTP-Tiny/corpus/redirect-16.txt | 47 +++++++++++++++++++++++++++++ + cpan/HTTP-Tiny/corpus/redirect-17.txt | 39 ++++++++++++++++++++++++ + cpan/HTTP-Tiny/corpus/redirect-18.txt | 38 +++++++++++++++++++++++ + cpan/HTTP-Tiny/corpus/redirect-19.txt | 40 ++++++++++++++++++++++++ + cpan/HTTP-Tiny/corpus/redirect-20.txt | 41 +++++++++++++++++++++++++ + cpan/HTTP-Tiny/lib/HTTP/Tiny.pm | 32 ++++++++++++++++---- + cpan/HTTP-Tiny/t/001_api.t | 5 +-- + 8 files changed, 291 insertions(+), 8 deletions(-) + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-15.txt + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-16.txt + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-17.txt + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-18.txt + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-19.txt + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-20.txt + +diff --git a/cpan/HTTP-Tiny/corpus/redirect-15.txt b/cpan/HTTP-Tiny/corpus/redirect-15.txt +new file mode 100644 +index 0000000..35eb003 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-15.txt +@@ -0,0 +1,57 @@ ++url ++ http://victim.example/secret ++expected ++ pwned ++expected_url ++ http://victim.example/back ++headers ++ Authorization: Bearer SECRET-TOKEN ++ Cookie: session=SECRET-SESSION ++ Proxy-Authorization: Basic c2VjcmV0OnNlY3JldA== ++---------- ++GET /secret HTTP/1.1 ++Host: victim.example ++Authorization: Bearer SECRET-TOKEN ++Cookie: session=SECRET-SESSION ++Proxy-Authorization: Basic c2VjcmV0OnNlY3JldA== ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: http://attacker.example/loot ++ ++redirect ++ ++---------- ++GET /loot HTTP/1.1 ++Host: attacker.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: http://victim.example/back ++ ++redirect ++ ++---------- ++GET /back HTTP/1.1 ++Host: victim.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 5 ++ ++pwned ++ +diff --git a/cpan/HTTP-Tiny/corpus/redirect-16.txt b/cpan/HTTP-Tiny/corpus/redirect-16.txt +new file mode 100644 +index 0000000..986a95d +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-16.txt +@@ -0,0 +1,47 @@ ++url ++ http://victim.example/secret ++expected ++ pwned ++expected_url ++ http://attacker.example/loot ++new_args ++ allow_credentialed_redirects: 1 ++headers ++ Authorization: Bearer SECRET-TOKEN ++ Cookie: session=SECRET-SESSION ++ Proxy-Authorization: Basic c2VjcmV0OnNlY3JldA== ++---------- ++GET /secret HTTP/1.1 ++Host: victim.example ++Authorization: Bearer SECRET-TOKEN ++Cookie: session=SECRET-SESSION ++Proxy-Authorization: Basic c2VjcmV0OnNlY3JldA== ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: http://attacker.example/loot ++ ++redirect ++ ++---------- ++GET /loot HTTP/1.1 ++Host: attacker.example ++Authorization: Bearer SECRET-TOKEN ++Cookie: session=SECRET-SESSION ++Proxy-Authorization: Basic c2VjcmV0OnNlY3JldA== ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 5 ++ ++pwned ++ +diff --git a/cpan/HTTP-Tiny/corpus/redirect-17.txt b/cpan/HTTP-Tiny/corpus/redirect-17.txt +new file mode 100644 +index 0000000..141dd6c +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-17.txt +@@ -0,0 +1,39 @@ ++url ++ http://example.com/a ++expected ++ ok ++expected_url ++ http://example.com/b ++headers ++ Authorization: Bearer SECRET-TOKEN ++---------- ++GET /a HTTP/1.1 ++Host: example.com ++Authorization: Bearer SECRET-TOKEN ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: http://example.com/b ++ ++redirect ++ ++---------- ++GET /b HTTP/1.1 ++Host: example.com ++Authorization: Bearer SECRET-TOKEN ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 2 ++ ++ok ++ +diff --git a/cpan/HTTP-Tiny/corpus/redirect-18.txt b/cpan/HTTP-Tiny/corpus/redirect-18.txt +new file mode 100644 +index 0000000..09e8073 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-18.txt +@@ -0,0 +1,38 @@ ++url ++ http://example.com:8080/foo ++expected ++ ok ++expected_url ++ http://example.com:8081/bar ++headers ++ Authorization: Bearer SECRET-TOKEN ++---------- ++GET /foo HTTP/1.1 ++Host: example.com:8080 ++Authorization: Bearer SECRET-TOKEN ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: http://example.com:8081/bar ++ ++redirect ++ ++---------- ++GET /bar HTTP/1.1 ++Host: example.com:8081 ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 2 ++ ++ok ++ +diff --git a/cpan/HTTP-Tiny/corpus/redirect-19.txt b/cpan/HTTP-Tiny/corpus/redirect-19.txt +new file mode 100644 +index 0000000..2b52d20 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-19.txt +@@ -0,0 +1,40 @@ ++url ++ https://example.com:8443/foo ++expected ++ ok ++expected_url ++ http://example.com:8443/foo ++new_args ++ allow_downgrade: 1 ++headers ++ Authorization: Bearer SECRET-TOKEN ++---------- ++GET /foo HTTP/1.1 ++Host: example.com:8443 ++Authorization: Bearer SECRET-TOKEN ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: http://example.com:8443/foo ++ ++redirect ++ ++---------- ++GET /foo HTTP/1.1 ++Host: example.com:8443 ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 2 ++ ++ok ++ +diff --git a/cpan/HTTP-Tiny/corpus/redirect-20.txt b/cpan/HTTP-Tiny/corpus/redirect-20.txt +new file mode 100644 +index 0000000..9553352 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-20.txt +@@ -0,0 +1,41 @@ ++url ++ http://victim.example/submit ++method ++ POST ++expected ++ ok ++expected_url ++ http://attacker.example/loot ++headers ++ Authorization: Bearer SECRET-TOKEN ++---------- ++POST /submit HTTP/1.1 ++Host: victim.example ++Authorization: Bearer SECRET-TOKEN ++Connection: close ++Content-Length: 0 ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 303 See Other ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: http://attacker.example/loot ++ ++redirect ++ ++---------- ++GET /loot HTTP/1.1 ++Host: attacker.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 2 ++ ++ok ++ +diff --git a/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm b/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm +index e4937cb..40682f8 100644 +--- a/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm ++++ b/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm +@@ -18,6 +18,12 @@ sub _croak { require Carp; Carp::croak(@_) } + #pod * C — A user-agent string (defaults to 'HTTP-Tiny/$VERSION'). If + #pod C — ends in a space character, the default user-agent string is + #pod appended. ++#pod * C - If a 3xx redirects to a different scheme, ++#pod host or port, by default HTTP::Tiny will strip away caller-supplied ++#pod C, C and C headers from the ++#pod redirected request and from all subsequent requests in the chain. Set this to a ++#pod true value to revert to the legacy behavior of forwarding those headers. ++#pod Default is C. + #pod * C — If a 3xx redirect changes the scheme from C to + #pod plain C, HTTP::Tiny will by default refuse to follow it, returning the + #pod 3xx response. Set this to a true value to revert to the legacy behavior of +@@ -76,9 +82,9 @@ sub _croak { require Carp; Carp::croak(@_) } + my @attributes; + BEGIN { + @attributes = qw( +- allow_downgrade cookie_jar default_headers http_proxy https_proxy +- keep_alive local_address max_redirect max_size proxy no_proxy +- SSL_options verify_SSL ++ allow_credentialed_redirects allow_downgrade cookie_jar default_headers ++ http_proxy https_proxy keep_alive local_address max_redirect max_size ++ proxy no_proxy SSL_options verify_SSL + ); + my %persist_ok = map {; $_ => 1 } qw( + cookie_jar default_headers max_redirect max_size +@@ -452,6 +458,7 @@ sub mirror { + #pod =cut + + my %idempotent = map { $_ => 1 } qw/GET HEAD PUT DELETE OPTIONS TRACE/; ++my %sensitive_headers = map { $_ => 1 } qw/authorization cookie proxy-authorization/; + + sub request { + my ($self, $method, $url, $args) = @_; +@@ -829,6 +836,7 @@ sub _prepare_headers_and_cb { + for ($self->{default_headers}, $args->{headers}) { + next unless defined; + while (my ($k, $v) = each %$_) { ++ next if $args->{_strip_credentials} && exists $sensitive_headers{lc $k}; + $request->{headers}{lc $k} = $v; + $request->{header_case}{lc $k} = $k; + } +@@ -959,10 +967,18 @@ sub _maybe_redirect { + my $location = ($headers->{location} =~ /^\//) + ? "$request->{scheme}://$request->{host_port}$headers->{location}" + : $headers->{location} ; +- my ($to_scheme) = $self->_split_url($location); ++ my ($to_scheme, $to_host, $to_port) = $self->_split_url($location); + if (!$self->{allow_downgrade} && $request->{scheme} eq 'https' && $to_scheme eq 'http' ) { + return; + } ++ if ( ++ !$self->{allow_credentialed_redirects} ++ && ( $request->{scheme} ne $to_scheme ++ || $request->{host} ne $to_host ++ || $request->{port} ne $to_port ) ++ ) { ++ $args->{_strip_credentials} = 1; ++ } + + return (($status eq '303' ? 'GET' : $method), $location); + } +@@ -1931,8 +1947,7 @@ Don't use C when you really want C. See L for + how this applies to redirection. + + If the URL includes a "user:password" stanza, they will be used for Basic-style +-authorization headers. (Authorization headers will not be included in a +-redirected request.) For example: ++authorization headers. For example: + + $http->request('GET', 'http://Aladdin:open sesame@example.com/'); + +@@ -1941,6 +1956,10 @@ be percent-escaped: + + $http->request('GET', 'http://john%40example.com:password@example.com/'); + ++Caller-supplied C, C and C headers ++are stripped on cross-origin redirects. See L's ++C attribute to opt out. ++ + A hashref of options may be appended to modify the request. + + Valid options are: +@@ -2078,6 +2097,7 @@ host has closed its end of the socket. + + =for Pod::Coverage SSL_options + agent ++allow_credentialed_redirects + allow_downgrade + cookie_jar + default_headers +diff --git a/cpan/HTTP-Tiny/t/001_api.t b/cpan/HTTP-Tiny/t/001_api.t +index 7e1fa57..403fff7 100644 +--- a/cpan/HTTP-Tiny/t/001_api.t ++++ b/cpan/HTTP-Tiny/t/001_api.t +@@ -7,8 +7,9 @@ use Test::More tests => 2; + use HTTP::Tiny; + + my @accessors = qw( +- agent allow_downgrade default_headers http_proxy https_proxy keep_alive local_address +- max_redirect max_size proxy no_proxy timeout SSL_options verify_SSL cookie_jar ++ agent allow_credentialed_redirects allow_downgrade default_headers http_proxy ++ https_proxy keep_alive local_address max_redirect max_size proxy no_proxy timeout ++ SSL_options verify_SSL cookie_jar + ); + my @methods = qw( + new get head put post patch delete post_form request mirror www_form_urlencode can_ssl diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-7017-3.diff perl-5.40.1/debian/patches/fixes/CVE-2026-7017-3.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-7017-3.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-7017-3.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,78 @@ +From: Olaf Alders +Date: Thu, 14 May 2026 20:18:15 +0000 +Subject: Fix protocol-relative Location handling so it can't be used to + bypass credential strip + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f +Bug: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36 +Bug-Debian: https://bugs.debian.org/1140152 +--- + cpan/HTTP-Tiny/corpus/redirect-21.txt | 38 +++++++++++++++++++++++++++++++++++ + cpan/HTTP-Tiny/lib/HTTP/Tiny.pm | 6 ++++-- + 2 files changed, 42 insertions(+), 2 deletions(-) + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-21.txt + +diff --git a/cpan/HTTP-Tiny/corpus/redirect-21.txt b/cpan/HTTP-Tiny/corpus/redirect-21.txt +new file mode 100644 +index 0000000..8670368 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-21.txt +@@ -0,0 +1,38 @@ ++url ++ https://victim.example/x ++expected ++ pwned ++expected_url ++ https://attacker.example/loot ++headers ++ Authorization: Bearer TRUSTED-TOKEN ++---------- ++GET /x HTTP/1.1 ++Host: victim.example ++Authorization: Bearer TRUSTED-TOKEN ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: //attacker.example/loot ++ ++redirect ++ ++---------- ++GET /loot HTTP/1.1 ++Host: attacker.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 5 ++ ++pwned ++ +diff --git a/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm b/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm +index 40682f8..0380cbf 100644 +--- a/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm ++++ b/cpan/HTTP-Tiny/lib/HTTP/Tiny.pm +@@ -964,9 +964,11 @@ sub _maybe_redirect { + and $headers->{location} + and @{$args->{_redirects}} < $self->{max_redirect} + ) { +- my $location = ($headers->{location} =~ /^\//) ++ my $location = $headers->{location} =~ m{^//} ++ ? "$request->{scheme}:$headers->{location}" ++ : $headers->{location} =~ m{^/} + ? "$request->{scheme}://$request->{host_port}$headers->{location}" +- : $headers->{location} ; ++ : $headers->{location}; + my ($to_scheme, $to_host, $to_port) = $self->_split_url($location); + if (!$self->{allow_downgrade} && $request->{scheme} eq 'https' && $to_scheme eq 'http' ) { + return; diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-7017-4.diff perl-5.40.1/debian/patches/fixes/CVE-2026-7017-4.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-7017-4.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-7017-4.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,62 @@ +From: Olaf Alders +Date: Thu, 14 May 2026 20:37:52 +0000 +Subject: demonstrate that https upgrade now strips credentials + +as it is a change of origin + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/0d7b31e7a16281e918e68fad855ddf249209b026 +Bug: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36 +Bug-Debian: https://bugs.debian.org/1140152 +--- + cpan/HTTP-Tiny/corpus/redirect-22.txt | 40 +++++++++++++++++++++++++++++++++++ + 1 file changed, 40 insertions(+) + create mode 100644 cpan/HTTP-Tiny/corpus/redirect-22.txt + +diff --git a/cpan/HTTP-Tiny/corpus/redirect-22.txt b/cpan/HTTP-Tiny/corpus/redirect-22.txt +new file mode 100644 +index 0000000..c5534a6 +--- /dev/null ++++ b/cpan/HTTP-Tiny/corpus/redirect-22.txt +@@ -0,0 +1,40 @@ ++url ++ http://example.com/login ++expected ++ ok ++expected_url ++ https://example.com/login ++headers ++ Authorization: Bearer SECRET-TOKEN ++ Cookie: session=SECRET-SESSION ++---------- ++GET /login HTTP/1.1 ++Host: example.com ++Authorization: Bearer SECRET-TOKEN ++Cookie: session=SECRET-SESSION ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: https://example.com/login ++ ++redirect ++ ++---------- ++GET /login HTTP/1.1 ++Host: example.com ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 2 ++ ++ok ++ diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-7017-5.diff perl-5.40.1/debian/patches/fixes/CVE-2026-7017-5.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-7017-5.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-7017-5.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,106 @@ +From: Olaf Alders +Date: Fri, 15 May 2026 20:48:11 +0000 +Subject: Add tests to cover redirects from requests providing basic auth via + the URL + + rather than a manually set Authorization header, with and without the + allow_credentialed_redirects option. + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d9aa62b0013abb790b3cf45340320fae475ffdb2 +Bug: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36 +Bug-Debian: https://bugs.debian.org/1140152 +--- + HTTP-Tiny/corpus/redirect-23.txt | 36 ++++++++++++++++++++++++++++++++++++ + HTTP-Tiny/corpus/redirect-24.txt | 38 ++++++++++++++++++++++++++++++++++++++ + 2 files changed, 74 insertions(+) + create mode 100644 HTTP-Tiny/corpus/redirect-23.txt + create mode 100644 HTTP-Tiny/corpus/redirect-24.txt + +diff --git a/HTTP-Tiny/corpus/redirect-23.txt b/HTTP-Tiny/corpus/redirect-23.txt +new file mode 100644 +index 0000000..de44874 +--- /dev/null ++++ b/HTTP-Tiny/corpus/redirect-23.txt +@@ -0,0 +1,36 @@ ++url ++ https://user:pass@victim.example/secret ++expected ++ ok ++expected_url ++ https://attacker.example/loot ++---------- ++GET /secret HTTP/1.1 ++Host: victim.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++Authorization: Basic dXNlcjpwYXNz ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: https://attacker.example/loot ++ ++redirect ++ ++---------- ++GET /loot HTTP/1.1 ++Host: attacker.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 2 ++ ++ok ++ +diff --git a/HTTP-Tiny/corpus/redirect-24.txt b/HTTP-Tiny/corpus/redirect-24.txt +new file mode 100644 +index 0000000..c203e97 +--- /dev/null ++++ b/HTTP-Tiny/corpus/redirect-24.txt +@@ -0,0 +1,38 @@ ++url ++ https://user:pass@victim.example/secret ++expected ++ ok ++expected_url ++ https://attacker.example/loot ++new_args ++ allow_credentialed_redirects: 1 ++---------- ++GET /secret HTTP/1.1 ++Host: victim.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++Authorization: Basic dXNlcjpwYXNz ++ ++---------- ++HTTP/1.1 302 Found ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 8 ++Location: https://attacker.example/loot ++ ++redirect ++ ++---------- ++GET /loot HTTP/1.1 ++Host: attacker.example ++Connection: close ++User-Agent: HTTP-Tiny/VERSION ++ ++---------- ++HTTP/1.1 200 OK ++Date: Thu, 03 Feb 1994 00:00:00 GMT ++Content-Type: text/plain ++Content-Length: 2 ++ ++ok ++ diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-8376-tests.diff perl-5.40.1/debian/patches/fixes/CVE-2026-8376-tests.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-8376-tests.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-8376-tests.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,57 @@ +From: Tony Cook +Date: Tue, 12 May 2026 14:47:31 +1000 +Subject: perl/perl-security#147: test cases + +The suggested case from the ticket and an alternative. + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl/perl5/commit/e842efdafe7c51a687a4907e4887988fe6a025ef +Bug-Debian: https://bugs.debian.org/1137345 +--- + t/re/pat_psycho.t | 18 ++++++++++++++++-- + 1 file changed, 16 insertions(+), 2 deletions(-) + +diff --git a/t/re/pat_psycho.t b/t/re/pat_psycho.t +index 3360395..73a7992 100644 +--- a/t/re/pat_psycho.t ++++ b/t/re/pat_psycho.t +@@ -10,7 +10,7 @@ + use strict; + use warnings; + use 5.010; +- ++use Config; + + sub run_tests; + +@@ -31,7 +31,7 @@ BEGIN { + + skip_all('$PERL_SKIP_PSYCHO_TEST set') if $ENV{PERL_SKIP_PSYCHO_TEST}; + +-plan tests => 15; # Update this when adding/deleting tests. ++plan tests => 17; # Update this when adding/deleting tests. + + run_tests() unless caller; + +@@ -211,6 +211,20 @@ EOF + + + } ++ ++ SKIP: ++ { # sec #147 ++ $Config{ptrsize} == 4 ++ or skip "these only fail on x32 and use too much memory on x64", 2; ++ local $::TODO = "This crashes"; ++ # original case ++ fresh_perl_like('/\x{10000}{1073741824}/', ++ qr/Regexp out of space/, {}, "ssize_t overflow"); ++ ++ # synthesized but similar case ++ fresh_perl_like('/(?:\x{10001}\x{10000}){536870912}/', ++ qr/Regexp out of space/, {}, "ssize_t overflow again"); ++ } + } # End of sub run_tests + + 1; diff -Nru perl-5.40.1/debian/patches/fixes/CVE-2026-8376.diff perl-5.40.1/debian/patches/fixes/CVE-2026-8376.diff --- perl-5.40.1/debian/patches/fixes/CVE-2026-8376.diff 1970-01-01 00:00:00.000000000 +0000 +++ perl-5.40.1/debian/patches/fixes/CVE-2026-8376.diff 2026-08-30 08:53:55.000000000 +0000 @@ -0,0 +1,43 @@ +From: Tony Cook +Date: Tue, 12 May 2026 14:51:00 +1000 +Subject: perl/perl-security#147: test against the actual character lengths + +(Backported for Debian by Niko Tyni) + +Origin: backport, https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c +Bug-Debian: https://bugs.debian.org/1137345 +--- + regcomp_study.c | 7 +++++++ + t/re/pat_psycho.t | 1 - + 2 files changed, 7 insertions(+), 1 deletion(-) + +diff --git a/regcomp_study.c b/regcomp_study.c +index 6f41860..209f497 100644 +--- a/regcomp_study.c ++++ b/regcomp_study.c +@@ -2769,6 +2769,13 @@ Perl_study_chunk(pTHX_ + (U8 *) SvEND(data->last_found)) + - (U8*)s; + l -= old; ++ ++ if (l > 0 && ++ (mincount >= SSize_t_MAX / (SSize_t)l ++ || old > SSize_t_MAX - mincount * (SSize_t)l)) { ++ FAIL("Regexp out of space"); ++ } ++ + /* Get the added string: */ + last_str = newSVpvn_utf8(s + old, l, UTF); + last_chrs = UTF ? utf8_length((U8*)(s + old), +diff --git a/t/re/pat_psycho.t b/t/re/pat_psycho.t +index 73a7992..9fd764f 100644 +--- a/t/re/pat_psycho.t ++++ b/t/re/pat_psycho.t +@@ -216,7 +216,6 @@ EOF + { # sec #147 + $Config{ptrsize} == 4 + or skip "these only fail on x32 and use too much memory on x64", 2; +- local $::TODO = "This crashes"; + # original case + fresh_perl_like('/\x{10000}{1073741824}/', + qr/Regexp out of space/, {}, "ssize_t overflow"); diff -Nru perl-5.40.1/debian/patches/series perl-5.40.1/debian/patches/series --- perl-5.40.1/debian/patches/series 2025-07-03 16:14:15.000000000 +0000 +++ perl-5.40.1/debian/patches/series 2026-08-30 08:53:55.000000000 +0000 @@ -46,3 +46,25 @@ fixes/CVE-2025-40909-2.diff fixes/CVE-2025-40909-3.diff fixes/CVE-2025-40909-metaconfig-reorder.diff +fixes/CVE-2026-8376-tests.diff +fixes/CVE-2026-8376.diff +fixes/CVE-2026-57432-1.diff +fixes/CVE-2026-57432-2.diff +fixes/CVE-2026-57433.diff +fixes/CVE-2026-7010.diff +fixes/CVE-2026-7010-tests.diff +fixes/CVE-2025-15649.diff +fixes/CVE-2025-15649-tests.diff +fixes/CVE-2026-48959.diff +fixes/CVE-2026-48961.diff +fixes/CVE-2026-48962.diff +fixes/CVE-2026-7017-1.diff +fixes/CVE-2026-7017-2.diff +fixes/CVE-2026-7017-3.diff +fixes/CVE-2026-7017-4.diff +fixes/CVE-2026-7017-5.diff +fixes/CVE-2026-42496-1.diff +fixes/CVE-2026-42496-2.diff +fixes/CVE-2026-13221.diff +fixes/CVE-2026-19487.diff +fixes/CVE-2026-12087.diff diff -Nru perl-5.40.1/debian/source/include-binaries perl-5.40.1/debian/source/include-binaries --- perl-5.40.1/debian/source/include-binaries 2025-06-27 17:09:37.000000000 +0000 +++ perl-5.40.1/debian/source/include-binaries 2026-08-30 08:49:28.000000000 +0000 @@ -39,3 +39,5 @@ debian/tests/data/s390x/buster-ndbm.pag debian/tests/data/s390x/stretch.gdbm debian/tests/data/s390x/stretch-ndbm.pag +# binary zip file for a test case +debian/patches/fixes/CVE-2025-15649.diff