UbuntuUpdates.org

Package "libnet-cidr-lite-perl"

Name: libnet-cidr-lite-perl

Description:

module for merging IPv4 or IPv6 CIDR address ranges

Latest version: 0.22-2ubuntu0.26.04.1
Release: resolute (26.04)
Level: security
Repository: main
Homepage: https://metacpan.org/release/Net-CIDR-Lite

Links


Download "libnet-cidr-lite-perl"


Other versions of "libnet-cidr-lite-perl" in Resolute

Repository Area Version
base main 0.22-2
updates main 0.22-2ubuntu0.26.04.1

Changelog

Version: 0.22-2ubuntu0.26.04.1 2026-06-08 19:07:43 UTC

  libnet-cidr-lite-perl (0.22-2ubuntu0.26.04.1) resolute-security; urgency=medium

  * SECURITY UPDATE: IP ACL Bypass via find()
    - debian/patches/CVE-2026-40198.patch: Reject uncompressed IPv6 addresses
      with fewer than 8 groups in Lite.pm
    - debian/patches/CVE-2026-40199.patch: Do not include sentinel byte when
      packing IPv4 mapped addresses in Lite.pm
    - CVE-2026-40198
    - CVE-2026-40199

 -- Kyle Kernick <email address hidden> Fri, 05 Jun 2026 10:00:33 -0600

CVE-2026-40198 Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that un
CVE-2026-40199 Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentin



About   -   Send Feedback to @ubuntu_updates