CVE-2016-6185: High severity Perl Perl vulnerability
Last updated 25 August 2025
Other sources
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/perlto a version that resolves this vulnerability.Fixed in 5.32.1-4+deb11u3Fixed in 5.32.1-4+deb11u5Fixed in 5.36.0-7+deb12u3Fixed in 5.36.0-7+deb12u2Fixed in 5.40.1-6Fixed in 5.40.1-8
Event History
Frequently Asked Questions
What is CVE-2016-6185?
CVE-2016-6185 is a vulnerability in the XSLoader::load method in Perl that allows local users to execute arbitrary code via a Trojan horse library.
How severe is CVE-2016-6185?
CVE-2016-6185 has a severity rating of 7.8 out of 10.
Which software is affected by CVE-2016-6185?
The affected software includes Perl 5.28.1-6+deb10u1, Perl 5.32.1-4+deb11u2, Perl 5.32.1-4+deb11u1, Perl 5.36.0-7, Perl 5.36.0-9, Perl Perl (version 5.24.1 to 5.25.3), Fedoraproject Fedora 22, Fedoraproject Fedora 23, Fedoraproject Fedora 24, Debian Debian Linux 8.0, Oracle Solaris 10, Oracle Solaris 11.3, Canonical Ubuntu Linux 12.04, Canonical Ubuntu Linux 14.04, Canonical Ubuntu Linux 16.04, and Canonical Ubuntu Linux 17.10.
How do I fix CVE-2016-6185 in Perl?
To fix CVE-2016-6185 in Perl, update to Perl version 5.28.1-6+deb10u1, 5.32.1-4+deb11u2, 5.32.1-4+deb11u1, 5.36.0-7, or 5.36.0-9.
Are there any references for CVE-2016-6185?
Yes, you can find references for CVE-2016-6185 at the following links: [CVE-2016-6185](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6185), [USN-3625-1](https://ubuntu.com/security/notices/USN-3625-1), [USN-3625-2](https://ubuntu.com/security/notices/USN-3625-2).