DEBIAN-CVE-2026-4176

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 29 Mar 2026, 21:16
Last modified:30 Mar 2026, 07:48

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Mar 2026, 21:16
Published
Vulnerability first disclosed
30 Mar 2026, 07:48
Last Modified
Vulnerability information updated

Description

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.

Affected Systems

  • debianperl

    < 5.10.0-21 | < 5.10.0-21 | < 5.10.0-21 | < 5.10.0-21

References (1)