CVE-2026-13221
ADVISORY - debianSummary
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.
[experimental] - perl 5.44.0-1
- perl 5.42.3-1 (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142037) [trixie] - perl 5.40.1-6+deb13u1 https://lists.security.metacpan.org/cve-announce/msg/41780104/ https://github.com/Perl/perl5/issues/23388 Introduced with: https://github.com/Perl/perl5/commit/acababb42be12ff2986b73c1bfa963b70bb5d54e (v5.37.10) Fixed by: https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7 (v5.43.10)
Common Weakness Enumeration (CWE)
Integer Overflow or Wraparound
Debian
-
| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| debian/perl | deb | debian | 12 | >0 | Not yet available |
| debian/perl | deb | debian | 13 | <5.40.1-6+deb13u1 | 5.40.1-6+deb13u1 |
| debian/perl | deb | debian | 14 | <5.42.3-1 | 5.42.3-1 |
| debian/perl | deb | debian | unstable | <5.42.3-1 | 5.42.3-1 |
Severity and metrics
No CVSS data available from this advisory.
NIST
3.9
CVSS SCORE
9.1criticalAlpine
-
Ubuntu
3.9
CVSS SCORE
9.1mediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumChainguard
CGA-7g6p-hrhh-4mjw
-
Photon
CVE-2026-13221
-
CVSS SCORE
9.1criticalminimos
MINI-2766-r85p-j4cp
-
minimos
MINI-ghgh-35v3-3mm5
-
minimos
MINI-h79w-p96m-84m7
-
minimos
MINI-ppxc-4vph-wfqh
-