CVE-2016-2381: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 9.1% chance of exploitation in the next 30 days.

Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Opensuse Opensuse: version 13.2 only
  • Oracle Communications Billing And Revenue Management: version 7.5 only
  • Oracle Configuration Manager: before 12.1.2.0.4 (fixed in 12.1.2.0.4); version 12.1.2.0.6 only
  • Oracle Database Server: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only; version 19c only
  • Oracle Enterprise Manager Base Platform: version 13.2.0.0.0 only; version 13.3.0.0.0 only
  • Oracle Solaris: version 11.3 only
  • Oracle Timesten In-Memory Database: before 18.1.2.1.0 (fixed in 18.1.2.1.0)
  • Perl Perl: before 5.23.9 (fixed in 5.23.9)

Published 2016-04-08. Last modified 2026-06-17.