Read and write compressed data
Go to file
RHEL Packaging Agent 983c1da5ec Fix CVE-2026-48962 in perl-IO-Compress File::GlobMapper
Backport fix for CVE-2026-48962 to perl-IO-Compress-2.102.
The patch removes unsafe eval STRING usage in File::GlobMapper
by replacing it with direct string substitution using internal
delimiter markers. Includes a follow-up fix for a regression
in wildcard replacement after ordinary letters. Both upstream
commits (f2db247 and 3651e9e) are combined into a single patch.

CVE: CVE-2026-48962
Upstream patches:
 - f2db247bf9.patch
 - 3651e9eb3f.patch
Resolves: RHEL-180410

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-07-22 08:31:06 +00:00
.fmf Merged update from upstream sources 2021-03-11 20:23:52 +00:00
plans Merged update from upstream sources 2021-03-11 20:23:52 +00:00
tests Merged update from upstream sources 2021-03-11 20:23:52 +00:00
.gitignore RHEL 9.0.0 Alpha bootstrap 2020-10-14 13:04:32 -07:00
gating.yaml Merged update from upstream sources 2021-03-11 20:23:52 +00:00
perl-IO-Compress-2.102-CVE-2026-48962.patch Fix CVE-2026-48962 in perl-IO-Compress File::GlobMapper 2026-07-22 08:31:06 +00:00
perl-IO-Compress.rpmlintrc RHEL 9.0.0 Alpha bootstrap 2020-10-14 13:04:32 -07:00
perl-IO-Compress.spec Fix CVE-2026-48962 in perl-IO-Compress File::GlobMapper 2026-07-22 08:31:06 +00:00
sources Merged update from upstream sources 2021-03-11 20:23:52 +00:00