The vendor explicitly identifies these products as affected by this CVE.
- perl as a component of Red Hat Enterprise Linux 8
- perl-Attribute-Handlers as a component of Red Hat Enterprise Linux 8
- perl-Devel-Peek as a component of Red Hat Enterprise Linux 8
- perl-Devel-SelfStubber as a component of Red Hat Enterprise Linux 8
- perl-Errno as a component of Red Hat Enterprise Linux 8
- perl-ExtUtils-Embed as a component of Red Hat Enterprise Linux 8
- perl-ExtUtils-Miniperl as a component of Red Hat Enterprise Linux 8
- perl-IO as a component of Red Hat Enterprise Linux 8
- perl-IO-Zlib as a component of Red Hat Enterprise Linux 8
- perl-Locale-Maketext-Simple as a component of Red Hat Enterprise Linux 8
- perl-Math-Complex as a component of Red Hat Enterprise Linux 8
- perl-Memoize as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in Perl, stemming from its inclusion of an outdated `Compress::Raw::Zlib` module. This module bundles a vulnerable version of the `zlib` library, which is known to contain multiple security flaws, including CVE-2026-3381 and CVE-2026-27171. Exploitation of these underlying vulnerabilities could lead to various security impacts, depending on the specific flaw within `zlib`.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
