Bug 35464 - perl-Starlet new security issue CVE-2026-40561
Summary: perl-Starlet new security issue CVE-2026-40561
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-05-04 11:09 CEST by Nicolas Salguero
Modified: 2026-05-07 11:10 CEST (History)
3 users (show)

See Also:
Source RPM: perl-Starlet-0.310.0-4.mga9.src.rpm
CVE: CVE-2026-40561
Status comment:
herman.viaene: test_passed_mga9_64+


Attachments

Nicolas Salguero 2026-05-04 11:10:55 CEST

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=35448
Flags: (none) => affects_mga9+
Status comment: (none) => Patch available from upstream
CVE: (none) => CVE-2026-40561
Source RPM: (none) => perl-Starlet-0.310.0-5.mga10.src.rpm, perl-Starlet-0.310.0-4.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 1 Nicolas Salguero 2026-05-04 11:30:31 CEST
For Cauldron, I asked for a freeze move.


Suggested advisory:
========================

The updated package fixes a security vulnerability:

Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence. (CVE-2026-40561)

References:
https://www.openwall.com/lists/oss-security/2026/05/03/1
https://datatracker.ietf.org/doc/html/rfc7230#section-3.3.3
========================

Updated package in core/updates_testing:
========================
perl-Starlet-0.310.0-4.1.mga9

from SRPM:
perl-Starlet-0.310.0-4.1.mga9.src.rpm

Status comment: Patch available from upstream => (none)
Flags: affects_mga9+ => (none)
Whiteboard: MGA9TOO => (none)
Source RPM: perl-Starlet-0.310.0-5.mga10.src.rpm, perl-Starlet-0.310.0-4.mga9.src.rpm => perl-Starlet-0.310.0-4.mga9.src.rpm
Version: Cauldron => 9
Status: NEW => ASSIGNED
Assignee: bugsquad => qa-bugs

Comment 2 Herman Viaene 2026-05-06 14:34:39 CEST
Same remarks as bug 35448, OK on clean install.

Flags: (none) => test_passed_mga9_64+
CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OK

Comment 3 Thomas Andrews 2026-05-06 23:05:46 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

katnatek 2026-05-07 04:38:29 CEST

Keywords: (none) => advisory

Comment 4 Mageia Robot 2026-05-07 07:09:17 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0120.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Nicolas Salguero 2026-05-07 11:10:38 CEST

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=35485


Note You need to log in before you can comment on or make changes to this bug.