Amazon Linux 2023 Security Advisory: ALAS2023-2026-2161
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-14
Socket versions before 2.041 for Perl have an out-of-bounds heap read.
In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.
Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure. (CVE-2026-12087)
Affected Packages:
perl-Socket
Issue Correction:
Run dnf update perl-Socket --releasever 2023.12.20260914 or dnf update --advisory ALAS2023-2026-2161 --releasever 2023.12.20260914 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
perl-Socket-debugsource-2.032-1.amzn2023.0.4.aarch64
perl-Socket-2.032-1.amzn2023.0.4.aarch64
perl-Socket-debuginfo-2.032-1.amzn2023.0.4.aarch64
perl-Socket-tests-2.032-1.amzn2023.0.4.aarch64
src:
perl-Socket-2.032-1.amzn2023.0.4.src
x86_64:
perl-Socket-debugsource-2.032-1.amzn2023.0.4.x86_64
perl-Socket-debuginfo-2.032-1.amzn2023.0.4.x86_64
perl-Socket-tests-2.032-1.amzn2023.0.4.x86_64
perl-Socket-2.032-1.amzn2023.0.4.x86_64