CVE-2026-42497 Affecting perl package, versions <5.38.2-3.2ubuntu0.3


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.42% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2404-PERL-16877231
  • published24 Aug 2026
  • disclosed26 May 2026

Introduced: 26 May 2026

CVE-2026-42497  (opens in a new tab)

How to fix?

Upgrade Ubuntu:24.04 perl to version 5.38.2-3.2ubuntu0.3 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Ubuntu. See How to fix? for Ubuntu:24.04 relevant fixed versions and status.

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.

_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.

A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

CVSS Base Scores

version 3.1