Description
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.

S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.

A template derived from untrusted input can read heap memory past the buffer and return it to the caller.
Published: 2026-07-13
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Disclosure
Action: Apply Patch
AI Analysis

Impact

Perl versions before 5.40.5‑RC1, from 5.41.0 before 5.42.3‑RC1, from 5.43.0 before 5.43.11 contain an integer overflow in the internal function S_measure_struct. The routine adds each item's size multiplied by its repeat count to a running total without an overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, allowing the buffer pointer to advance out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller, exposing confidential information.

Affected Systems

Perl releases up to and including version 5.43.10 are affected. The fix was incorporated into the 5.43.11 development release, so systems running 5.43.10 or earlier should upgrade to 5.43.11 or a later version.

Risk and Exploitability

The CVSS score of 8.4 and an EPSS score of < 1% indicate a high potential impact but a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can supply a malicious pack or unpack template derived from untrusted input—such as user‑controlled scripts or web applications that process external data—thereby triggering the out‑of‑bounds read. Successful exploitation would be local to the environment that executes the Perl code, but the compromised data can potentially be exfiltrated if the process has network access or is part of a larger compromised system.

Generated by OpenCVE AI on September 10, 2026 at 04:58 UTC.

Remediation

Vendor Solution

Upgrade to Perl 5.40.5, 5.42.3 or 5.44.0 or later, or apply the upstream patches.


OpenCVE Recommended Actions

  • Upgrade to Perl 5.43.11 or a later release to apply the upstream patch.
  • Avoid executing pack or unpack functions with templates derived from untrusted input; if such input must be processed, validate repeat counts before invocation.
  • Implement stricter input sanitization or replace vulnerable pack/unpack usage in critical code paths with safer alternatives when feasible.

Generated by OpenCVE AI on September 10, 2026 at 04:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8684-1 Perl vulnerabilities
History

Tue, 08 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller. Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.
Title Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Shay
Shay perl
Vendors & Products Shay
Shay perl

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.
Title Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Weaknesses CWE-125
CWE-190
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-08T21:32:25.884Z

Reserved: 2026-06-24T13:09:26.322Z

Link: CVE-2026-57432

cve-icon Vulnrichment

Updated: 2026-07-13T19:30:46.712Z

cve-icon NVD

Status : Modified

Published: 2026-07-13T17:17:55.670

Modified: 2026-09-08T22:18:30.640

Link: CVE-2026-57432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:00:09Z

Weaknesses