[security][CVE-2026-42497] perl-base in runtime images #138

Open
opened 2026-07-16 13:21:09 +00:00 by dirtydishes · 0 comments
Owner

Automation detected a newly untracked active high-severity CVE in the shipped runtime surface.

  • CVE: CVE-2026-42497
  • Affected component: perl-base in runtime images
  • Severity: HIGH
  • In-repo version(s): perl-base 5.40.1-6 in oven/bun:1.3.11 and 5.36.0-7+deb12u3 in redis:7.2
  • Project impact: Both shipped base images carry vulnerable Perl archive-handling code, so hardlink extraction from attacker-controlled tar input can escape the intended directory inside the container.
  • Remediation: Move to refreshed base images once Debian packages or upstream images include the fixed Perl/Archive::Tar release.

Counters for this run:

  • unaddressed critical CVEs: 6
  • unaddressed medium/low CVEs: 119
  • unaddressed total CVEs: 163

Sources:

Automation detected a newly untracked active high-severity CVE in the shipped runtime surface. - CVE: CVE-2026-42497 - Affected component: perl-base in runtime images - Severity: HIGH - In-repo version(s): perl-base 5.40.1-6 in oven/bun:1.3.11 and 5.36.0-7+deb12u3 in redis:7.2 - Project impact: Both shipped base images carry vulnerable Perl archive-handling code, so hardlink extraction from attacker-controlled tar input can escape the intended directory inside the container. - Remediation: Move to refreshed base images once Debian packages or upstream images include the fixed Perl/Archive::Tar release. Counters for this run: - unaddressed critical CVEs: 6 - unaddressed medium/low CVEs: 119 - unaddressed total CVEs: 163 Sources: - https://nvd.nist.gov/vuln/detail/CVE-2026-42497 - https://avd.aquasec.com/nvd/cve-2026-42497
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#138
No description provided.