CVE-2026-8376: Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
Last updated 26 June 2026
Other sources
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/perlto a version that resolves this vulnerability.Fixed in 5.40.1-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.38.2-511 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.38.2-512 - Upgrade
Upgrade
perlto a version that resolves this vulnerability.Fixed in 5.43.10 - Compensating control
Mitigate by avoiding compilation of attacker-controlled regular expressions with repeated fixed substrings (especially on 32-bit Perl builds) until the upstream patch or a future Perl release is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8376?
The severity of CVE-2026-8376 is rated as risk level 28.
How do I fix CVE-2026-8376?
To fix CVE-2026-8376, upgrade to a future release of Perl or apply the upstream patch.
What versions of Perl are affected by CVE-2026-8376?
Perl versions through 5.43.10 are affected by CVE-2026-8376.
What type of vulnerability is CVE-2026-8376?
CVE-2026-8376 is classified as a buffer overflow vulnerability.
On which builds is CVE-2026-8376 a concern?
CVE-2026-8376 is a concern specifically on 32-bit builds of Perl.