ALAS2023-2026-2161


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2161
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-14
Severity: Low

Issue Overview:

Socket versions before 2.041 for Perl have an out-of-bounds heap read.

In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.

Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure. (CVE-2026-12087)


Affected Packages:

perl-Socket


Issue Correction:
Run dnf update perl-Socket --releasever 2023.12.20260914 or dnf update --advisory ALAS2023-2026-2161 --releasever 2023.12.20260914 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    perl-Socket-debugsource-2.032-1.amzn2023.0.4.aarch64
    perl-Socket-2.032-1.amzn2023.0.4.aarch64
    perl-Socket-debuginfo-2.032-1.amzn2023.0.4.aarch64
    perl-Socket-tests-2.032-1.amzn2023.0.4.aarch64

src:
    perl-Socket-2.032-1.amzn2023.0.4.src

x86_64:
    perl-Socket-debugsource-2.032-1.amzn2023.0.4.x86_64
    perl-Socket-debuginfo-2.032-1.amzn2023.0.4.x86_64
    perl-Socket-tests-2.032-1.amzn2023.0.4.x86_64
    perl-Socket-2.032-1.amzn2023.0.4.x86_64