Debian Package Tracker
Register | Log in
Subscribe

libxs-parse-keyword-perl

XS functions to assist in parsing keyword syntax

Choose email to subscribe with

general
  • source: libxs-parse-keyword-perl (main)
  • version: 0.51-1
  • maintainer: Debian Perl Group (archive) (DMD) (LowNMU)
  • uploaders: gregor herrmann [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 0.33-1
  • stable: 0.48-2
  • testing: 0.49-1
  • unstable: 0.51-1
versioned links
  • 0.33-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.48-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.49-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.51-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libxs-parse-keyword-perl
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-85644: XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references, but it tests using SvRV() rather than SvROK(). SvRV() reads a union slot that only holds a referent once SvROK(sv) is true, so the guard never validates that it is a reference. For an IV or NV that slot holds the number itself, SvRV() returns the caller's value and SvTYPE() dereferences it at offset 12. This will generally result in a segmentation fault. An application that hands the wrapper a list built from decoded input (for example, from JSON) lets whoever supplies a number in that list choose the address that the interpreter dereferences. An ordinary string's byte 12 is rarely SVt_PVAV so the guard croaks by luck, but an attacker-crafted string carrying 0x0b there passes, and the buffer is then used as an AV head, with AvARRAY taken from bytes 16-23 and its entries pushed onto the Perl stack as live SVs. A simple proof-of-concept uses the zip operator: use Syntax::Operator::Zip 'zip'; my @args = ([1], 2); zip(@args);
Created: 2026-09-28 Last update: 2026-09-30 00:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-85644: XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references, but it tests using SvRV() rather than SvROK(). SvRV() reads a union slot that only holds a referent once SvROK(sv) is true, so the guard never validates that it is a reference. For an IV or NV that slot holds the number itself, SvRV() returns the caller's value and SvTYPE() dereferences it at offset 12. This will generally result in a segmentation fault. An application that hands the wrapper a list built from decoded input (for example, from JSON) lets whoever supplies a number in that list choose the address that the interpreter dereferences. An ordinary string's byte 12 is rarely SVt_PVAV so the guard croaks by luck, but an attacker-crafted string carrying 0x0b there passes, and the buffer is then used as an AV head, with AvARRAY taken from bytes 16-23 and its entries pushed onto the Perl stack as live SVs. A simple proof-of-concept uses the zip operator: use Syntax::Operator::Zip 'zip'; my @args = ([1], 2); zip(@args);
Created: 2026-09-28 Last update: 2026-09-30 00:30
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-85644: (needs triaging) XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references, but it tests using SvRV() rather than SvROK(). SvRV() reads a union slot that only holds a referent once SvROK(sv) is true, so the guard never validates that it is a reference. For an IV or NV that slot holds the number itself, SvRV() returns the caller's value and SvTYPE() dereferences it at offset 12. This will generally result in a segmentation fault. An application that hands the wrapper a list built from decoded input (for example, from JSON) lets whoever supplies a number in that list choose the address that the interpreter dereferences. An ordinary string's byte 12 is rarely SVt_PVAV so the guard croaks by luck, but an attacker-crafted string carrying 0x0b there passes, and the buffer is then used as an AV head, with AvARRAY taken from bytes 16-23 and its entries pushed onto the Perl stack as live SVs. A simple proof-of-concept uses the zip operator: use Syntax::Operator::Zip 'zip'; my @args = ([1], 2); zip(@args);

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-28 Last update: 2026-09-30 00:30
testing migrations
  • excuses:
    • Migration status for libxs-parse-keyword-perl (0.49-1 to 0.51-1): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for libfuture-asyncawait-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for liblist-keywords-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libobject-pad-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsyntax-infix-smartmatch-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsyntax-keyword-assert-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsyntax-keyword-dynamically-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsyntax-keyword-match-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsyntax-keyword-try-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsyntax-operator-equ-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsyntax-operator-in-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsyntax-operator-is-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libxs-parse-keyword-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Lintian check waiting for test results on riscv64 - info
    • ∙ ∙ Too young, only 0 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/libx/libxs-parse-keyword-perl.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-09-29] Accepted libxs-parse-keyword-perl 0.51-1 (source) into unstable (gregor herrmann)
  • [2025-09-30] libxs-parse-keyword-perl 0.49-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-27] Accepted libxs-parse-keyword-perl 0.49-1 (source) into unstable (gregor herrmann)
  • [2025-01-28] libxs-parse-keyword-perl 0.48-2 MIGRATED to testing (Debian testing watch)
  • [2025-01-24] Accepted libxs-parse-keyword-perl 0.48-2 (source) into unstable (gregor herrmann)
  • [2025-01-15] libxs-parse-keyword-perl 0.48-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-12] Accepted libxs-parse-keyword-perl 0.48-1 (source) into unstable (gregor herrmann)
  • [2024-12-10] libxs-parse-keyword-perl 0.47-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-07] Accepted libxs-parse-keyword-perl 0.47-1 (source) into unstable (gregor herrmann)
  • [2024-09-06] libxs-parse-keyword-perl 0.46-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-03] Accepted libxs-parse-keyword-perl 0.46-1 (source) into unstable (gregor herrmann)
  • [2024-09-01] libxs-parse-keyword-perl 0.44-2 MIGRATED to testing (Debian testing watch)
  • [2024-08-26] Accepted libxs-parse-keyword-perl 0.44-2 (source) into unstable (gregor herrmann)
  • [2024-07-24] Accepted libxs-parse-keyword-perl 0.44-1 (source) into unstable (gregor herrmann)
  • [2024-05-17] libxs-parse-keyword-perl 0.42-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-08] Accepted libxs-parse-keyword-perl 0.42-1 (source) into unstable (gregor herrmann)
  • [2024-05-03] libxs-parse-keyword-perl 0.41-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-27] Accepted libxs-parse-keyword-perl 0.41-1 (source) into unstable (gregor herrmann)
  • [2023-12-10] libxs-parse-keyword-perl 0.39-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-07] Accepted libxs-parse-keyword-perl 0.39-1 (source) into unstable (gregor herrmann)
  • [2023-08-12] libxs-parse-keyword-perl 0.38-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-12] libxs-parse-keyword-perl 0.38-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-09] Accepted libxs-parse-keyword-perl 0.38-1 (source) into unstable (gregor herrmann)
  • [2023-07-27] libxs-parse-keyword-perl 0.36-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-24] Accepted libxs-parse-keyword-perl 0.36-1 (source) into unstable (gregor herrmann)
  • [2023-06-24] libxs-parse-keyword-perl 0.34-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-21] Accepted libxs-parse-keyword-perl 0.34-1 (source) into unstable (gregor herrmann)
  • [2023-03-03] libxs-parse-keyword-perl 0.33-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-20] Accepted libxs-parse-keyword-perl 0.33-1 (source) into unstable (gregor herrmann)
  • [2023-01-26] libxs-parse-keyword-perl 0.32-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.49-1build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing