<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for perl is now available for openEuler-24.03-LTS-SP1</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2026-3932</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2026-09-20</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2026-09-20</InitialReleaseDate>
		<CurrentReleaseDate>2026-09-20</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2026-09-20</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">perl security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for perl is now available for openEuler-24.03-LTS-SP1</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">Perl 5 is a highly capable, feature-rich programming language with over 30 years of development. Perl 5 runs on over 100 platforms from portables to mainframes and is suitable for both rapid prototyping and large scale development projects.

Security Fix(es):

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.

The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.

Example:

  &quot;ABCDE&quot; =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE
  &quot;ABCDE&quot; =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed

An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.(CVE-2026-19487)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for perl is now available for openEuler-24.03-LTS-SP1.

openEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">Medium</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">perl</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3932</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-19487</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-19487</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-24.03-LTS-SP1" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">openEuler-24.03-LTS-SP1</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="aarch64">
			<FullProductName ProductID="perl-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-5.38.0-18.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="perl-debuginfo-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-debuginfo-5.38.0-18.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="perl-debugsource-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-debugsource-5.38.0-18.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="perl-devel-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-devel-5.38.0-18.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="perl-libs-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-libs-5.38.0-18.oe2403sp1.aarch64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="perl-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-5.38.0-18.oe2403sp1.src.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="x86_64">
			<FullProductName ProductID="perl-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-5.38.0-18.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="perl-debuginfo-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-debuginfo-5.38.0-18.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="perl-debugsource-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-debugsource-5.38.0-18.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="perl-devel-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-devel-5.38.0-18.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="perl-libs-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-libs-5.38.0-18.oe2403sp1.x86_64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="noarch">
			<FullProductName ProductID="perl-help-5.38.0-18" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">perl-help-5.38.0-18.oe2403sp1.noarch.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.

The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.

Example:

  &quot;ABCDE&quot; =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE
  &quot;ABCDE&quot; =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed

An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.</Note>
		</Notes>
		<ReleaseDate>2026-09-20</ReleaseDate>
		<CVE>CVE-2026-19487</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP1</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>5.3</BaseScore>
				<Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>perl security update</Description>
				<DATE>2026-09-20</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3932</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>