OPENSUSE-SU-2026:21177-1
Vulnerability from csaf_opensuse - Published: 2026-06-30 09:10 - Updated: 2026-09-17 17:37Summary
Security update for perl-IO-Compress
Severity
Important
Notes
Title of the patch: Security update for perl-IO-Compress
Description of the patch: This update for perl-IO-Compress fixes the following issues:
Changes in perl-IO-Compress:
- updated to 2.220.0 (2.220)
see /usr/share/doc/packages/perl-IO-Compress/Changes
2.220 16 May 2026
* remove use of eval in globmapper. #73
CVE-2026-48962 bsc#1266382
* Update zipdetails to version 4.006.
CVE-2026-48961 bsc#1266381
* Fix typo in fastForward #72
* Fix issue with "rawdeflate` option in AnyInflate. #71
- updated to 2.219.0 (2.219)
see /usr/share/doc/packages/perl-IO-Compress/Changes
2.219 9 March 2026
* Fix a few typos
* Squash repeated semicolons
* Make dependent version checking consistent amd update module to version 2.219. Fixes #70
2.218 8 March 2026
* Refresh zipdetails to version 4.005 Sourced from https://github.com/pmqs/zipdetails
* version 2.218
* Add SECURITY.md, Fixes #69
* fix spelling typo
* Refresh Changes file
* Update release date in README
* Refresh zipdetails from https://github.com/pmqs/zipdetails
2.217 1 February 2026
* Update release date in README
* Refresh zipdetails from https://github.com/pmqs/zipdetails
* Delete GZIP environment variable before running interop tests Fixes #24
* Update version to 2.217
2.216 31 January 2026
* Update version to 2.216
* IO::Compress @2.215: t/006zip.t fails due to missing test files #67
2.215 31 January 2026
* Fix version check in 000prereq.t
* Update Changes for 2.215
* Update version to 2.215 & change copyright year to 2026
* Add tests for handling zero and invalid datetime values in unzip functionality. Fix for #65
* Enhance _dosToUnixTime to handle zero and invalid datetime values; add tests for edge cases. Fixes #65
- updated to 2.214.0 (2.214)
see /usr/share/doc/packages/perl-IO-Compress/Changes
2.214 24 October 2025
* version 2.214
* IO::Compress::Gzip accidentally modifies the `$EXPORT_TAGS{all}->@*` of other modules Fixes #64
* Fix indentation in Windows workflow YAML
* Fix indentation in windows.yml exclude section
* Merge pull request #63 from masiuchi/fix/ci-errors
* Exclude Perl 5.42 with "strawberry" distribution from GitHub Actions
* Update FreeBSD image to 14.3 in Cirrus CI
* Add dependabot.yml file to police workflow files
* Add perl 5.42 to workflow files
* Fix for https://github.com/pmqs/Compress-Raw-Zlib/issues/34
* #59 fix typos in streamzip
Patchnames: openSUSE-Leap-16.0-packagehub-372
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Recommended
1 product
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: openSUSE Leap 16.0:perl-IO-Compress-0:2.220.0-bp160.1.1.noarch | — |
Vendor Fix
|
Threats
Impact
important
Affected products
Recommended
1 product, the same list as for
CVE-2026-48961
Threats
Impact
important
References
11 references
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "important"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "Security update for perl-IO-Compress",
"title": "Title of the patch"
},
{
"category": "description",
"text": "This update for perl-IO-Compress fixes the following issues:\n\nChanges in perl-IO-Compress:\n\n- updated to 2.220.0 (2.220)\n see /usr/share/doc/packages/perl-IO-Compress/Changes\n\n 2.220 16 May 2026\n * remove use of eval in globmapper. #73\n CVE-2026-48962 bsc#1266382\n * Update zipdetails to version 4.006.\n CVE-2026-48961 bsc#1266381\n * Fix typo in fastForward #72\n * Fix issue with \"rawdeflate` option in AnyInflate. #71\n\n- updated to 2.219.0 (2.219)\n see /usr/share/doc/packages/perl-IO-Compress/Changes\n\n 2.219 9 March 2026\n * Fix a few typos\n * Squash repeated semicolons\n * Make dependent version checking consistent amd update module to version 2.219. Fixes #70\n 2.218 8 March 2026\n * Refresh zipdetails to version 4.005 Sourced from https://github.com/pmqs/zipdetails\n * version 2.218\n * Add SECURITY.md, Fixes #69\n * fix spelling typo\n * Refresh Changes file\n * Update release date in README\n * Refresh zipdetails from https://github.com/pmqs/zipdetails\n 2.217 1 February 2026\n * Update release date in README\n * Refresh zipdetails from https://github.com/pmqs/zipdetails\n * Delete GZIP environment variable before running interop tests Fixes #24\n * Update version to 2.217\n 2.216 31 January 2026\n * Update version to 2.216\n * IO::Compress @2.215: t/006zip.t fails due to missing test files #67\n 2.215 31 January 2026\n * Fix version check in 000prereq.t\n * Update Changes for 2.215\n * Update version to 2.215 \u0026 change copyright year to 2026\n * Add tests for handling zero and invalid datetime values in unzip functionality. Fix for #65\n * Enhance _dosToUnixTime to handle zero and invalid datetime values; add tests for edge cases. Fixes #65\n\n- updated to 2.214.0 (2.214)\n see /usr/share/doc/packages/perl-IO-Compress/Changes\n\n 2.214 24 October 2025\n * version 2.214\n * IO::Compress::Gzip accidentally modifies the `$EXPORT_TAGS{all}-\u003e@*` of other modules Fixes #64\n * Fix indentation in Windows workflow YAML\n * Fix indentation in windows.yml exclude section\n * Merge pull request #63 from masiuchi/fix/ci-errors\n * Exclude Perl 5.42 with \"strawberry\" distribution from GitHub Actions\n * Update FreeBSD image to 14.3 in Cirrus CI\n * Add dependabot.yml file to police workflow files\n * Add perl 5.42 to workflow files\n * Fix for https://github.com/pmqs/Compress-Raw-Zlib/issues/34\n * #59 fix typos in streamzip\n",
"title": "Description of the patch"
},
{
"category": "details",
"text": "openSUSE-Leap-16.0-packagehub-372",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_21177-1.json"
},
{
"category": "self",
"summary": "SUSE Bug 1266381",
"url": "https://bugzilla.suse.com/1266381"
},
{
"category": "self",
"summary": "SUSE Bug 1266382",
"url": "https://bugzilla.suse.com/1266382"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-48961 page",
"url": "https://www.suse.com/security/cve/CVE-2026-48961/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-48962 page",
"url": "https://www.suse.com/security/cve/CVE-2026-48962/"
}
],
"title": "Security update for perl-IO-Compress",
"tracking": {
"current_release_date": "2026-09-17T17:37:13Z",
"generator": {
"date": "2026-06-30T09:10:12Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "openSUSE-SU-2026:21177-1",
"initial_release_date": "2026-06-30T09:10:12Z",
"revision_history": [
{
"date": "2026-06-30T09:10:12Z",
"number": "1",
"summary": "Current version"
},
{
"date": "2026-09-16T20:40:20Z",
"number": "2",
"summary": "unknown changes"
},
{
"date": "2026-09-16T21:42:20Z",
"number": "3",
"summary": "unknown changes"
},
{
"date": "2026-09-17T17:37:13Z",
"number": "4",
"summary": "unknown changes"
}
],
"status": "final",
"version": "4"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "perl-IO-Compress-0:2.220.0-bp160.1.1.noarch",
"product": {
"name": "perl-IO-Compress-0:2.220.0-bp160.1.1.noarch",
"product_id": "perl-IO-Compress-0:2.220.0-bp160.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/perl-IO-Compress@2.220.0-bp160.1.1?arch=noarch"
}
}
}
],
"category": "architecture",
"name": "noarch"
},
{
"branches": [
{
"category": "product_name",
"name": "openSUSE Leap 16.0",
"product": {
"name": "openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0"
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "perl-IO-Compress-0:2.220.0-bp160.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:perl-IO-Compress-0:2.220.0-bp160.1.1.noarch"
},
"product_reference": "perl-IO-Compress-0:2.220.0-bp160.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-48961",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-48961"
}
],
"notes": [
{
"category": "general",
"text": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises \u0027Undefined subroutine \u0026main::unpackValueQ\u0027 and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:perl-IO-Compress-0:2.220.0-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-48961",
"url": "https://www.suse.com/security/cve/CVE-2026-48961"
},
{
"category": "external",
"summary": "SUSE Bug 1266381 for CVE-2026-48961",
"url": "https://bugzilla.suse.com/1266381"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:perl-IO-Compress-0:2.220.0-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-06-30T09:10:12Z",
"details": "important"
}
],
"title": "CVE-2026-48961"
},
{
"cve": "CVE-2026-48962",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-48962"
}
],
"notes": [
{
"category": "general",
"text": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process\u0027s privilege.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:perl-IO-Compress-0:2.220.0-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-48962",
"url": "https://www.suse.com/security/cve/CVE-2026-48962"
},
{
"category": "external",
"summary": "SUSE Bug 1266382 for CVE-2026-48962",
"url": "https://bugzilla.suse.com/1266382"
},
{
"category": "external",
"summary": "SUSE Bug 1275554 for CVE-2026-48962",
"url": "https://bugzilla.suse.com/1275554"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:perl-IO-Compress-0:2.220.0-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-06-30T09:10:12Z",
"details": "important"
}
],
"title": "CVE-2026-48962"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…