[security][CVE-2026-8376] perl-base in runtime images #140

Open
opened 2026-07-16 13:21:09 +00:00 by dirtydishes · 0 comments
Owner

Automation detected a newly untracked active high-severity CVE in the shipped runtime surface.

  • CVE: CVE-2026-8376
  • Affected component: perl-base in runtime images
  • Severity: CRITICAL
  • In-repo version(s): perl-base 5.40.1-6 in oven/bun:1.3.11 and 5.36.0-7+deb12u3 in redis:7.2
  • Project impact: Both shipped base images carry vulnerable Perl archive-handling code, so crafted tar headers can exhaust memory in any in-container Perl archive-processing path.
  • Remediation: Move to refreshed base images once Debian packages or upstream images include the fixed Perl/Archive::Tar release.

Counters for this run:

  • unaddressed critical CVEs: 6
  • unaddressed medium/low CVEs: 119
  • unaddressed total CVEs: 163

Sources:

Automation detected a newly untracked active high-severity CVE in the shipped runtime surface. - CVE: CVE-2026-8376 - Affected component: perl-base in runtime images - Severity: CRITICAL - In-repo version(s): perl-base 5.40.1-6 in oven/bun:1.3.11 and 5.36.0-7+deb12u3 in redis:7.2 - Project impact: Both shipped base images carry vulnerable Perl archive-handling code, so crafted tar headers can exhaust memory in any in-container Perl archive-processing path. - Remediation: Move to refreshed base images once Debian packages or upstream images include the fixed Perl/Archive::Tar release. Counters for this run: - unaddressed critical CVEs: 6 - unaddressed medium/low CVEs: 119 - unaddressed total CVEs: 163 Sources: - https://nvd.nist.gov/vuln/detail/CVE-2026-8376 - https://avd.aquasec.com/nvd/cve-2026-8376
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#140
No description provided.