{"schema_version":"1.7.2","id":"OESA-2026-2789","modified":"2026-08-06T11:11:42Z","published":"2026-06-24T11:11:42Z","upstream":["CVE-2026-11526"],"summary":"perl-GD security update","details":"This is a autoloadable interface module for libgd, a popular library for creating and manipulating PNG files.  With this library you can create PNG images on the fly or modify existing files.  Features include:\r\n\r\nSecurity Fix(es):\n\nGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle.\n\nGD::Image::_make_filehandle opens a filename argument with Perl&apos;s 2-arg open(), so a filename that begins or ends with a pipe (&quot;| cmd&quot;, &quot;cmd |&quot;) or begins with a redirect (&quot;&gt; path&quot;, &quot;&gt;&gt; path&quot;) is run as a command or redirect rather than opened as a file. _make_filehandle is the single open path behind every filename-accepting constructor (new, newFromPng, newFromJpeg, and the rest); the in-memory *Data variants do not open a path and are unaffected.\n\nAny caller that forwards untrusted input to one of these constructors as a pathname can run an arbitrary command or truncate a file under the process UID.(CVE-2026-11526)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP3","name":"perl-GD","purl":"pkg:rpm/openEuler/perl-GD&distro=openEuler-24.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.78-2.oe2403sp3"}]}],"ecosystem_specific":{"aarch64":["perl-GD-2.78-2.oe2403sp3.aarch64.rpm","perl-GD-debuginfo-2.78-2.oe2403sp3.aarch64.rpm","perl-GD-debugsource-2.78-2.oe2403sp3.aarch64.rpm"],"noarch":["perl-GD-help-2.78-2.oe2403sp3.noarch.rpm"],"src":["perl-GD-2.78-2.oe2403sp3.src.rpm"],"x86_64":["perl-GD-2.78-2.oe2403sp3.x86_64.rpm","perl-GD-debuginfo-2.78-2.oe2403sp3.x86_64.rpm","perl-GD-debugsource-2.78-2.oe2403sp3.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:20.03-LTS-SP4","name":"perl-GD","purl":"pkg:rpm/openEuler/perl-GD&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.72-3.oe2003sp4"}]}],"ecosystem_specific":{"aarch64":["perl-GD-2.72-3.oe2003sp4.aarch64.rpm","perl-GD-debuginfo-2.72-3.oe2003sp4.aarch64.rpm","perl-GD-debugsource-2.72-3.oe2003sp4.aarch64.rpm"],"noarch":["perl-GD-help-2.72-3.oe2003sp4.noarch.rpm"],"src":["perl-GD-2.72-3.oe2003sp4.src.rpm"],"x86_64":["perl-GD-2.72-3.oe2003sp4.x86_64.rpm","perl-GD-debuginfo-2.72-3.oe2003sp4.x86_64.rpm","perl-GD-debugsource-2.72-3.oe2003sp4.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:22.03-LTS-SP4","name":"perl-GD","purl":"pkg:rpm/openEuler/perl-GD&distro=openEuler-22.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.75-3.oe2203sp4"}]}],"ecosystem_specific":{"aarch64":["perl-GD-2.75-3.oe2203sp4.aarch64.rpm","perl-GD-debuginfo-2.75-3.oe2203sp4.aarch64.rpm","perl-GD-debugsource-2.75-3.oe2203sp4.aarch64.rpm"],"noarch":["perl-GD-help-2.75-3.oe2203sp4.noarch.rpm"],"src":["perl-GD-2.75-3.oe2203sp4.src.rpm"],"x86_64":["perl-GD-2.75-3.oe2203sp4.x86_64.rpm","perl-GD-debuginfo-2.75-3.oe2203sp4.x86_64.rpm","perl-GD-debugsource-2.75-3.oe2203sp4.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:24.03-LTS-SP1","name":"perl-GD","purl":"pkg:rpm/openEuler/perl-GD&distro=openEuler-24.03-LTS-SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.78-2.oe2403sp1"}]}],"ecosystem_specific":{"aarch64":["perl-GD-2.78-2.oe2403sp1.aarch64.rpm","perl-GD-debuginfo-2.78-2.oe2403sp1.aarch64.rpm","perl-GD-debugsource-2.78-2.oe2403sp1.aarch64.rpm"],"noarch":["perl-GD-help-2.78-2.oe2403sp1.noarch.rpm"],"src":["perl-GD-2.78-2.oe2403sp1.src.rpm"],"x86_64":["perl-GD-2.78-2.oe2403sp1.x86_64.rpm","perl-GD-debuginfo-2.78-2.oe2403sp1.x86_64.rpm","perl-GD-debugsource-2.78-2.oe2403sp1.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2789"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11526"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"database_specific":{"severity":"Critical"}}
