RHSA-2026:30843: Important: perl-IO-Compress security update
Important: perl-IO-Compress security update
Other sources
This distribution provides a Perl interface to allow reading and writing of compressed data created with the zlib and bzip2 libraries. IO-Compress supports reading and writing of bzip2, RFC 1950, RFC 1951, RFC 1952 (i.e. gzip) and zip files/buffers. The following modules used to be distributed separately, but are now included with the IO-Compress distribution: Compress-Zlib IO-Compress-Zlib IO-Compress-Bzip2 IO-Compress-Base Security Fix(es): perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:30843?
The severity of RHSA-2026:30843 is considered high with a rating of 7.
How do I fix RHSA-2026:30843?
To fix RHSA-2026:30843, you should update the perl-IO-Compress package to the latest version available in your Red Hat repository.
What vulnerabilities does RHSA-2026:30843 address?
RHSA-2026:30843 addresses vulnerabilities related to the handling of compressed data in the perl-IO-Compress library.
Which systems are affected by RHSA-2026:30843?
RHSA-2026:30843 affects various Red Hat Enterprise Linux Server versions including those supporting IBM Power and z Systems.
What is the title of the advisory RHSA-2026:30843?
The title of the advisory RHSA-2026:30843 is 'Important: perl-IO-Compress security update'.