Updated perl-Net-CIDR-Lite packages fix security vulnerabilities
Publication date: 07 May 2026Modification date: 07 May 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-40198 , CVE-2026-40199
Description
Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6
group count, which may allow IP ACL bypass. (CVE-2026-40198)
Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped
IPv6 addresses, which may allow IP ACL bypass. (CVE-2026-40199)
References
- https://bugs.mageia.org/show_bug.cgi?id=35348
- https://www.openwall.com/lists/oss-security/2026/04/11/1
- https://www.openwall.com/lists/oss-security/2026/04/11/2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SKKSURTDDZIA5TCZ3QL5KFVFSKVVMRSQ/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40198
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40199
SRPMS
9/core
- perl-Net-CIDR-Lite-0.230.0-1.mga9