Debian Package Tracker
Register | Log in
Subscribe

libsocket-perl

networking constants and support functions

Choose email to subscribe with

general
  • source: libsocket-perl (main)
  • version: 2.041-1
  • maintainer: Debian Perl Group (archive) (DMD) (LowNMU)
  • uploaders: gregor herrmann [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.031-1
  • oldstable: 2.036-1
  • stable: 2.038-1
  • testing: 2.041-1
  • unstable: 2.041-1
versioned links
  • 2.031-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.036-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.038-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.041-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libsocket-perl
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-12087: Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.
Created: 2026-06-16 Last update: 2026-06-16 09:02
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-12087: Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.
Created: 2026-06-16 Last update: 2026-06-16 09:02
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-12087: Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.
Created: 2026-06-16 Last update: 2026-06-16 09:02
news
[rss feed]
  • [2026-05-23] libsocket-perl 2.041-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-06] Accepted libsocket-perl 2.041-1 (source) into unstable (gregor herrmann)
  • [2025-10-08] libsocket-perl 2.040-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-04] Accepted libsocket-perl 2.040-1 (source) into unstable (gregor herrmann)
  • [2024-05-03] libsocket-perl 2.038-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-19] Accepted libsocket-perl 2.038-1 (source) into unstable (gregor herrmann)
  • [2023-06-27] libsocket-perl 2.037-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-24] Accepted libsocket-perl 2.037-1 (source) into unstable (gregor herrmann)
  • [2022-08-24] libsocket-perl 2.036-1 MIGRATED to testing (Debian testing watch)
  • [2022-08-22] Accepted libsocket-perl 2.036-1 (source) into unstable (gregor herrmann)
  • [2022-07-07] libsocket-perl 2.035-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-01] Accepted libsocket-perl 2.035-1 (source) into unstable (gregor herrmann)
  • [2022-05-10] libsocket-perl 2.033-1 MIGRATED to testing (Debian testing watch)
  • [2022-05-07] Accepted libsocket-perl 2.033-1 (source) into unstable (gregor herrmann)
  • [2021-09-21] libsocket-perl 2.032-1 MIGRATED to testing (Debian testing watch)
  • [2021-09-18] Accepted libsocket-perl 2.032-1 (source) into unstable (gregor herrmann)
  • [2021-01-10] libsocket-perl 2.031-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-10] libsocket-perl 2.031-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-06] Accepted libsocket-perl 2.031-1 (source) into unstable (gregor herrmann)
  • [2020-07-13] libsocket-perl 2.030-1 MIGRATED to testing (Debian testing watch)
  • [2020-07-10] Accepted libsocket-perl 2.030-1 (source) into unstable (gregor herrmann)
  • [2019-03-08] libsocket-perl 2.029-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-25] Accepted libsocket-perl 2.029-1 (source) into unstable (gregor herrmann)
  • [2018-11-01] libsocket-perl 2.027-2 MIGRATED to testing (Debian testing watch)
  • [2018-10-29] Accepted libsocket-perl 2.027-2 (source) into unstable (intrigeri)
  • [2018-01-18] libsocket-perl 2.027-1 MIGRATED to testing (Debian testing watch)
  • [2018-01-13] Accepted libsocket-perl 2.027-1 (source) into unstable (gregor herrmann)
  • [2018-01-12] Accepted libsocket-perl 2.026-1 (source) into unstable (gregor herrmann)
  • [2016-08-18] libsocket-perl 2.024-1 MIGRATED to testing (Debian testing watch)
  • [2016-08-12] Accepted libsocket-perl 2.024-1 (source) into unstable (Nick Morrott) (signed by: gregor herrmann)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.040-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing