boks Index
Docs Releases

perl

1 tool · 4 release lines

Perl runtime + cpan/perldoc/prove. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing perl from perl@latest → 5.44.0 stable perl@5.40 → 5.40.5 stable perl@5.42 → 5.42.3 stable perl@5.44 → 5.44.0 stable

Findings

M1

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-15534 ↗ M 5.7 perl Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.

These are the findings of perl, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

C2H1M3

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-8376 ↗ C 9.8 perl Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
CVE-2026-13221 ↗ C 9.1 perl Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.
CVE-2026-57432 ↗ H 8.4 perl Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.
CVE-2025-40909 ↗ M 5.9 perl Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone…
CVE-2026-15534 ↗ M 5.7 perl Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.
CVE-2026-19487 ↗ M 5.3 perl Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.

These are the findings of perl, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

C2H1M1

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-8376 ↗ C 9.8 perl Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
CVE-2026-13221 ↗ C 9.1 perl Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.
CVE-2026-57432 ↗ H 8.4 perl Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.
CVE-2026-15534 ↗ M 5.7 perl Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.

These are the findings of perl, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

M1

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-15534 ↗ M 5.7 perl Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.

These are the findings of perl, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default + env
runtime none — self-contained
composes env

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/perl:5.44.0
digest
platforms
size 85 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/perl:5.40.5
digest
platforms
size 85 MB unpacked · 1 layer
base scratch
signed not signed
last scan

Image

image ghcr.io/boks-sh/perl:5.42.3
digest
platforms
size 83 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/perl:5.44.0
digest
platforms
size 85 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

perl

capabilities

rw

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

attestation arm64 — none amd64 — none
scan report arm64 ↗ amd64 ↗ grype ·

Every image ships a full SBOM. Nothing here is a claim you have to take on trust. Build attestation is not published yet.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

1 findings across this project at latest, 6 at 5.40 . Counted once per advisory across every image the project builds.