Impact
Perl versions before 5.40.5‑RC1, from 5.41.0 before 5.42.3‑RC1, from 5.43.0 before 5.43.11 contain an integer overflow in the internal function S_measure_struct. The routine adds each item's size multiplied by its repeat count to a running total without an overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, allowing the buffer pointer to advance out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller, exposing confidential information.
Affected Systems
Perl releases up to and including version 5.43.10 are affected. The fix was incorporated into the 5.43.11 development release, so systems running 5.43.10 or earlier should upgrade to 5.43.11 or a later version.
Risk and Exploitability
The CVSS score of 8.4 and an EPSS score of < 1% indicate a high potential impact but a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can supply a malicious pack or unpack template derived from untrusted input—such as user‑controlled scripts or web applications that process external data—thereby triggering the out‑of‑bounds read. Successful exploitation would be local to the environment that executes the Perl code, but the compromised data can potentially be exfiltrated if the process has network access or is part of a larger compromised system.
OpenCVE Enrichment
Ubuntu USN