RHSA-2026:48225HighCVSS 7.5

Red Hat Security Advisory: perl:5.32 security update

Published
July 30, 2026
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-9538 — perl-Archive-Tar: perl-Archive-Tar: Denial of Service via crafted tar header with large entry size

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 8)
  • perl-4:5.32.1-474.module+el8.10.0+24099+8aa2f756.aarch64 (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-4:5.32.1-474.module+el8.10.0+24099+8aa2f756.ppc64le (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-4:5.32.1-474.module+el8.10.0+24099+8aa2f756.s390x (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-4:5.32.1-474.module+el8.10.0+24099+8aa2f756.src (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-4:5.32.1-474.module+el8.10.0+24099+8aa2f756.x86_64 (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-Algorithm-Diff-0:1.1903-10.module+el8.10.0+21354+3ad137bb.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-Algorithm-Diff-0:1.1903-10.module+el8.10.0+21354+3ad137bb.src (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-Archive-Tar-0:2.38-5.module+el8.10.0+24544+66a14188.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-Archive-Tar-0:2.38-5.module+el8.10.0+24544+66a14188.src (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-Archive-Zip-0:1.68-3.module+el8.10.0+21354+3ad137bb.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-Archive-Zip-0:1.68-3.module+el8.10.0+21354+3ad137bb.src (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-Attribute-Handlers-0:1.01-474.module+el8.10.0+24099+8aa2f756.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-AutoLoader-0:5.74-474.module+el8.10.0+24099+8aa2f756.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-AutoSplit-0:5.74-474.module+el8.10.0+24099+8aa2f756.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-B-0:1.80-474.module+el8.10.0+24099+8aa2f756.aarch64 (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-B-0:1.80-474.module+el8.10.0+24099+8aa2f756.ppc64le (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-B-0:1.80-474.module+el8.10.0+24099+8aa2f756.s390x (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-B-0:1.80-474.module+el8.10.0+24099+8aa2f756.x86_64 (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-B-debuginfo-0:1.80-474.module+el8.10.0+24099+8aa2f756.aarch64 (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-B-debuginfo-0:1.80-474.module+el8.10.0+24099+8aa2f756.ppc64le (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-B-debuginfo-0:1.80-474.module+el8.10.0+24099+8aa2f756.s390x (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-B-debuginfo-0:1.80-474.module+el8.10.0+24099+8aa2f756.x86_64 (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-Benchmark-0:1.23-474.module+el8.10.0+24099+8aa2f756.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-CPAN-0:2.28-5.module+el8.10.0+21354+3ad137bb.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-CPAN-0:2.28-5.module+el8.10.0+21354+3ad137bb.src (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-CPAN-DistnameInfo-0:0.12-13.module+el8.10.0+21354+3ad137bb.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-CPAN-DistnameInfo-0:0.12-13.module+el8.10.0+21354+3ad137bb.src (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-CPAN-Meta-0:2.150010-397.module+el8.10.0+21354+3ad137bb.noarch (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • perl-CPAN-Meta-0:2.150010-397.module+el8.10.0+21354+3ad137bb.src (perl:5.32) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, avoid processing untrusted tar archives with applications using Perl's Archive::Tar module. If untrusted tar processing is required, consider imposing resource limits (e.g., ulimit) on the processes handling tar files to contain memory exhaustion and prevent wider system impact.

🔗 References (4)