Skip to main content
EPSS 0.4%top 63%

Red Hat Security Advisory: perl security update

0
Medium
Published: 09/14/2026 (09/14/2026, 07:33:58 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A security vulnerability identified as CVE-2026-13221 affects Perl, a widely used high-level programming language. The issue involves incorrect processing of large regular expressions, which could lead to unexpected behavior or potential security risks. Red Hat has issued a security advisory addressing this vulnerability with updated Perl packages. The severity of this vulnerability is assessed as medium. Multiple specific Perl versions used in Red Hat and Ubuntu distributions are affected. No known exploits are reported in the wild. Users are advised to apply the official updates provided by Red Hat to mitigate the risk.

Affected software

Ubuntu:Pro:14.04:LTSmore threats →ghsa
perl
pkg:deb/ubuntu/[email protected]+esm7?arch=source&distro=esm-infra-legacy/trusty
Affected versions
=5.14.2-21build1=5.18.1-4=5.18.1-4build1=5.18.1-5=5.18.2-2=5.18.2-2ubuntu1=5.18.2-2ubuntu1.1=5.18.2-2ubuntu1.3=5.18.2-2ubuntu1.4=5.18.2-2ubuntu1.6=5.18.2-2ubuntu1.7=5.18.2-2ubuntu1.7+esm3=5.18.2-2ubuntu1.7+esm4=5.18.2-2ubuntu1.7+esm5=5.18.2-2ubuntu1.7+esm7
Ubuntu:Pro:16.04:LTSmore threats →ghsa
perl
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenial
Affected versions
=5.20.2-6=5.22.1-3=5.22.1-4=5.22.1-5=5.22.1-7=5.22.1-8=5.22.1-9=5.22.1-9ubuntu0.2=5.22.1-9ubuntu0.3=5.22.1-9ubuntu0.5=5.22.1-9ubuntu0.6=5.22.1-9ubuntu0.9=5.22.1-9ubuntu0.9+esm1=5.22.1-9ubuntu0.9+esm2
Ubuntu:Pro:18.04:LTSmore threats →ghsa
perl
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra/bionic
Affected versions
=5.26.0-8ubuntu1=5.26.1-2ubuntu1=5.26.1-3=5.26.1-4=5.26.1-4build1=5.26.1-5=5.26.1-6=5.26.1-6ubuntu0.1=5.26.1-6ubuntu0.2=5.26.1-6ubuntu0.3=5.26.1-6ubuntu0.5=5.26.1-6ubuntu0.6=5.26.1-6ubuntu0.7=5.26.1-6ubuntu0.7+esm2
Ubuntu:Pro:20.04:LTSmore threats →ghsa
perl
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra/focal
Affected versions
=5.28.1-6build1=5.30.0-7=5.30.0-9=5.30.0-9build1=5.30.0-9ubuntu0.2=5.30.0-9ubuntu0.3=5.30.0-9ubuntu0.4=5.30.0-9ubuntu0.5=5.30.0-9ubuntu0.5+esm2
Ubuntu:22.04:LTSmore threats →ghsa
perl
pkg:deb/ubuntu/[email protected]?arch=source&distro=jammy
Affected versions
=5.32.1-3ubuntu3=5.34.0-3ubuntu1=5.34.0-3ubuntu1.1=5.34.0-3ubuntu1.2=5.34.0-3ubuntu1.3=5.34.0-3ubuntu1.4=5.34.0-3ubuntu1.5=5.34.0-3ubuntu1.7
Ubuntu:24.04:LTSmore threats →ghsa
perl
pkg:deb/ubuntu/[email protected]?arch=source&distro=noble
Affected versions
=5.36.0-9ubuntu1=5.36.0-10ubuntu1=5.38.2-3=5.38.2-3.2=5.38.2-3.2build1=5.38.2-3.2build2=5.38.2-3.2build2.1=5.38.2-3.2ubuntu0.1=5.38.2-3.2ubuntu0.2=5.38.2-3.2ubuntu0.3
Ubuntu:26.04:LTSmore threats →ghsa
perl
pkg:deb/ubuntu/[email protected]?arch=source&distro=resolute
Affected versions
=5.40.1-6build1=5.40.1-7build1=5.40.1-7ubuntu0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 02:20:28 UTC

Technical Analysis

CVE-2026-13221 is a vulnerability in Perl involving incorrect regular expression processing when handling large regular expressions. This flaw could cause improper behavior in Perl scripts that utilize complex regex patterns. Red Hat has released updated RPM packages for Perl and related modules to address this issue. The advisory covers numerous Perl versions across Red Hat Hardened Images and Red Hat Enterprise Linux distributions. There is no indication of active exploitation in the wild. The vulnerability is categorized with CWE-625 (Improper Control of a Resource Through its Lifetime) and CWE-125 (Out-of-bounds Read).

Potential Impact

The vulnerability may allow attackers or malicious scripts to cause unexpected behavior or potentially crash Perl processes by exploiting the incorrect handling of large regular expressions. This could affect system utilities or web applications relying on Perl for processing. However, no known active exploits have been reported, and the impact is considered medium severity.

Mitigation Recommendations

Red Hat has released official security updates that fix this vulnerability. Users should apply the updated Perl packages as provided in the Red Hat Security Advisory RHSA-2026:39997. Applying these updates will mitigate the vulnerability. There are no indications that additional mitigations are required beyond installing the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
UBUNTU-CVE-2026-13221
Osv Schema Version
1.7.0
Ecosystems
["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a58b4f968715ace43db21f4

Added to database: 07/16/2026, 10:39:53 UTC

Last enriched: 09/15/2026, 02:20:28 UTC

Last updated: 09/15/2026, 02:20:28 UTC

Views: 43

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses