mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 04:50:21 +00:00
perl: 5.42.0 -> 5.42.3
5.42.3 ships the interpreter fixes and the updated dual-life modules, so
the CVE-2026-8376 patch and every vendoredPerlDistributions entry are
dropped.
perl-cross 1.6.4 has no patch set for 5.42.3, so the perl5-5.42.0 set,
which applies unchanged, is vendored under the name perl-cross expects.
- perl: CVE-2026-13221, CVE-2026-57432, CVE-2026-8376
https://metacpan.org/release/SHAY/perl-5.42.3/view/pod/perldelta.pod
- HTTP-Tiny 0.096: CVE-2026-7010, CVE-2026-7017
https://metacpan.org/release/HAARG/HTTP-Tiny-0.096/changes
- Socket 2.041: CVE-2026-12087
https://metacpan.org/release/PEVANS/Socket-2.041/changes
- Storable 3.37_01: CVE-2026-57433
- Archive-Tar 3.12, Compress-Raw-Bzip2 2.218, Compress-Raw-Zlib 2.222,
IO-Compress 2.223
Assisted-by: Claude Code (Claude Opus 5)
Signed-off-by: Stig Palmquist <git@stig.io>
(cherry picked from commit 7b1e682245)
This commit is contained in:
committed by
Vladimír Čunát
parent
e7b465b341
commit
6a215dec0d
@@ -1,20 +0,0 @@
|
||||
Targeted patch for CVE-2026-8376, based on 5e7f119eb2bb1181be908701f22bf7068e722f1c but avoids changes to t/re/pat_psycho.t as they do not apply cleanly.
|
||||
|
||||
diff --git a/regcomp_study.c b/regcomp_study.c
|
||||
index b513454a4258..1602663f4b26 100644
|
||||
--- a/regcomp_study.c
|
||||
+++ b/regcomp_study.c
|
||||
@@ -2784,6 +2784,13 @@ Perl_study_chunk(pTHX_
|
||||
(U8 *) SvEND(data->last_found))
|
||||
- (U8*)s;
|
||||
l -= old;
|
||||
+
|
||||
+ if (l > 0 &&
|
||||
+ (mincount >= SSize_t_MAX / (SSize_t)l
|
||||
+ || old > SSize_t_MAX - mincount * (SSize_t)l)) {
|
||||
+ FAIL("Regexp out of space");
|
||||
+ }
|
||||
+
|
||||
/* Get the added string: */
|
||||
last_str = newSVpvn_utf8(s + old, l, UTF);
|
||||
last_chrs = UTF ? utf8_length((U8*)(s + old),
|
||||
@@ -73,8 +73,8 @@ in
|
||||
rec {
|
||||
perl5 = callPackage ./interpreter.nix {
|
||||
self = perl5;
|
||||
version = "5.42.0";
|
||||
sha256 = "sha256-4JPvGE1/mhuXl+JGUpb1VRCtttq4hCsMPtUzKWYwltw=";
|
||||
version = "5.42.3";
|
||||
sha256 = "sha256-ETd0CYWDe1zfFfDPq5Miedy0NS+RL+1vwUTotPCCNic=";
|
||||
inherit passthruFun;
|
||||
};
|
||||
}
|
||||
|
||||
@@ -36,8 +36,6 @@ let
|
||||
commonPatches = [
|
||||
# Do not look in /usr etc. for dependencies.
|
||||
./no-sys-dirs.patch
|
||||
|
||||
./CVE-2026-8376.patch
|
||||
]
|
||||
|
||||
# Fix build on Solaris on x86_64
|
||||
@@ -83,48 +81,7 @@ let
|
||||
|
||||
# Inject fixed CPAN releases for bundled dual-life distributions until the
|
||||
# next perl maintenance release includes them.
|
||||
vendoredPerlDistributions = [
|
||||
{
|
||||
# CVE-2026-7010
|
||||
path = "cpan/HTTP-Tiny";
|
||||
src = fetchurl {
|
||||
url = "mirror://cpan/authors/id/H/HA/HAARG/HTTP-Tiny-0.094.tar.gz";
|
||||
hash = "sha256-poQemfwbVdFd6VlHzL17dnvsxRxxAhl/qPBE333cB0M=";
|
||||
};
|
||||
}
|
||||
{
|
||||
# CVE-2026-3381, CVE-2026-4176
|
||||
path = "cpan/Compress-Raw-Zlib";
|
||||
src = fetchurl {
|
||||
url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Zlib-2.222.tar.gz";
|
||||
hash = "sha256-Hf19URplVifIGBXTDTurwo+luIRV/wP4sECZ3LUShrg=";
|
||||
};
|
||||
}
|
||||
{
|
||||
# Runtime dependency of IO-Compress 2.220.
|
||||
path = "cpan/Compress-Raw-Bzip2";
|
||||
src = fetchurl {
|
||||
url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Bzip2-2.218.tar.gz";
|
||||
hash = "sha256-iRU+ai69pSNJSTsHT6S3VJ/x+QU952E8GKXgXFtBX6g=";
|
||||
};
|
||||
}
|
||||
{
|
||||
# CVE-2026-48962, CVE-2026-48961, CVE-2026-48959
|
||||
path = "cpan/IO-Compress";
|
||||
src = fetchurl {
|
||||
url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz";
|
||||
hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic=";
|
||||
};
|
||||
}
|
||||
{
|
||||
# CVE-2026-42496, CVE-2026-42497, CVE-2026-9538
|
||||
path = "cpan/Archive-Tar";
|
||||
src = fetchurl {
|
||||
url = "mirror://cpan/authors/id/B/BI/BINGOS/Archive-Tar-3.12.tar.gz";
|
||||
hash = "sha256-ARTvObZfSfiWgoOrR3Gdfoj5jXNg/jZJvjMcf1PVgyw=";
|
||||
};
|
||||
}
|
||||
];
|
||||
vendoredPerlDistributions = [ ];
|
||||
|
||||
replaceVendoredPerlDistributions = lib.concatMapStringsSep "\n" (d: ''
|
||||
rm -rf ${d.path}
|
||||
@@ -440,6 +397,8 @@ stdenv.mkDerivation (
|
||||
# fixes build failure due to missing d_fdopendir/HAS_FDOPENDIR configure option
|
||||
# https://github.com/arsv/perl-cross/pull/159
|
||||
./cross-fdopendir.patch
|
||||
|
||||
./perl-cross-1.6.4--5.42.3.patch
|
||||
];
|
||||
|
||||
depsBuildBuild = [
|
||||
|
||||
@@ -0,0 +1,86 @@
|
||||
perl-cross 1.6.4 ships no patch set for perl 5.42.3. The perl5-5.42.0 set
|
||||
applies unchanged, so link it under the name perl-cross looks for. The
|
||||
links are per-file because `find cnf/diffs/perl5-$version`, which
|
||||
perl-cross uses to collect them, does not descend into a symlinked
|
||||
directory.
|
||||
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/constant.patch b/cnf/diffs/perl5-5.42.3/constant.patch
|
||||
new file mode 120000
|
||||
index 0000000..61f792a
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/constant.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/constant.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/dynaloader.patch b/cnf/diffs/perl5-5.42.3/dynaloader.patch
|
||||
new file mode 120000
|
||||
index 0000000..543415e
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/dynaloader.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/dynaloader.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/findext.patch b/cnf/diffs/perl5-5.42.3/findext.patch
|
||||
new file mode 120000
|
||||
index 0000000..94ed668
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/findext.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/findext.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/installscripts.patch b/cnf/diffs/perl5-5.42.3/installscripts.patch
|
||||
new file mode 120000
|
||||
index 0000000..6f715b4
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/installscripts.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/installscripts.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/liblist.patch b/cnf/diffs/perl5-5.42.3/liblist.patch
|
||||
new file mode 120000
|
||||
index 0000000..5037380
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/liblist.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/liblist.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/makemaker.patch b/cnf/diffs/perl5-5.42.3/makemaker.patch
|
||||
new file mode 120000
|
||||
index 0000000..cf9fc6c
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/makemaker.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/makemaker.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/posix-makefile.patch b/cnf/diffs/perl5-5.42.3/posix-makefile.patch
|
||||
new file mode 120000
|
||||
index 0000000..072ba89
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/posix-makefile.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/posix-makefile.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/test-checkcase.patch b/cnf/diffs/perl5-5.42.3/test-checkcase.patch
|
||||
new file mode 120000
|
||||
index 0000000..6ecc9bc
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/test-checkcase.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/test-checkcase.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/test-makemaker.patch b/cnf/diffs/perl5-5.42.3/test-makemaker.patch
|
||||
new file mode 120000
|
||||
index 0000000..fc6bcda
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/test-makemaker.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/test-makemaker.patch
|
||||
\ No newline at end of file
|
||||
diff --git a/cnf/diffs/perl5-5.42.3/xconfig.patch b/cnf/diffs/perl5-5.42.3/xconfig.patch
|
||||
new file mode 120000
|
||||
index 0000000..87ac501
|
||||
--- /dev/null
|
||||
+++ b/cnf/diffs/perl5-5.42.3/xconfig.patch
|
||||
@@ -0,0 +1 @@
|
||||
+../perl5-5.42.0/xconfig.patch
|
||||
\ No newline at end of file
|
||||
Reference in New Issue
Block a user