Security update for perl-Date-Manip
This security update for perl-Date-Manip addresses two vulnerabilities: CVE-2026-60074, which causes corrupted dates when processing non-ASCII decimal digits that pass numeric range checks, and CVE-2026-60075, which leads to CPU exhaustion due to quadratic backtracking in the unanchored time substitution in the _parse_time function. Both issues have been fixed in this update.
AI Analysis
Technical Summary
The perl-Date-Manip package contained two vulnerabilities. CVE-2026-60074 involves corrupted date outputs when non-ASCII decimal digits that pass numeric range tests are processed by the check function. CVE-2026-60075 involves a performance issue where CPU exhaustion can occur due to quadratic backtracking in the unanchored time substitution within the _parse_time function. These issues were identified and fixed by the SUSE Product Security Team as part of a security update.
Potential Impact
Exploitation of CVE-2026-60074 could result in incorrect date processing, potentially affecting applications relying on accurate date manipulation. CVE-2026-60075 could be exploited to cause denial of service via CPU exhaustion due to inefficient regex backtracking. Both vulnerabilities pose a high severity risk due to potential application disruption and resource exhaustion.
Mitigation Recommendations
Apply the security update provided by the SUSE Product Security Team for perl-Date-Manip to remediate these vulnerabilities. Since this is an official security update, installing the patch will resolve the issues. No additional mitigations are specified.
Security update for perl-Date-Manip
Description
This security update for perl-Date-Manip addresses two vulnerabilities: CVE-2026-60074, which causes corrupted dates when processing non-ASCII decimal digits that pass numeric range checks, and CVE-2026-60075, which leads to CPU exhaustion due to quadratic backtracking in the unanchored time substitution in the _parse_time function. Both issues have been fixed in this update.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The perl-Date-Manip package contained two vulnerabilities. CVE-2026-60074 involves corrupted date outputs when non-ASCII decimal digits that pass numeric range tests are processed by the check function. CVE-2026-60075 involves a performance issue where CPU exhaustion can occur due to quadratic backtracking in the unanchored time substitution within the _parse_time function. These issues were identified and fixed by the SUSE Product Security Team as part of a security update.
Potential Impact
Exploitation of CVE-2026-60074 could result in incorrect date processing, potentially affecting applications relying on accurate date manipulation. CVE-2026-60075 could be exploited to cause denial of service via CPU exhaustion due to inefficient regex backtracking. Both vulnerabilities pose a high severity risk due to potential application disruption and resource exhaustion.
Mitigation Recommendations
Apply the security update provided by the SUSE Product Security Team for perl-Date-Manip to remediate these vulnerabilities. Since this is an official security update, installing the patch will resolve the issues. No additional mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:21552-1
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-60075"]
- State
- PUBLISHED
Threat ID: 6aab496255bf5e2cf5990b0c
Added to database: 09/17/2026, 01:58:58 UTC
Last enriched: 09/17/2026, 02:09:20 UTC
Last updated: 09/17/2026, 02:09:20 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.