Description
Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.

S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.

A template derived from untrusted input can read heap memory past the buffer and return it to the caller.
Published: 2026-07-13
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Perl versions through 5.43.10 contain an integer overflow in the internal function S_measure_struct, which accumulates item sizes for pack and unpack templates without performing an overflow check. When a template specifies an exceedingly large repeat count, the signed length checks incorrectly succeed, allowing the buffer pointer to advance beyond its intended bounds and read arbitrary heap memory. The data read in this manner is then returned to the caller, enabling disclosure of confidential information.

Affected Systems

Perl releases up to and including version 5.43.10 are affected. The fix was incorporated into the 5.43.11 development release, so systems running 5.43.10 or earlier should upgrade to 5.43.11 or a later version.

Risk and Exploitability

The CVSS score of 8.4 and an EPSS score of < 1% indicate a high potential impact but a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can supply a malicious pack or unpack template derived from untrusted input—such as user‑controlled scripts or web applications that process external data—thereby triggering the out‑of‑bounds read. Successful exploitation would be local to the environment that executes the Perl code, but the compromised data can potentially be exfiltrated if the process has network access or is part of a larger compromised system.

Generated by OpenCVE AI on July 31, 2026 at 11:34 UTC.

Remediation

Vendor Solution

Apply the upstream patches. The fix is included in the Perl 5.43.11 development release.


OpenCVE Recommended Actions

  • Upgrade to Perl 5.43.11 or a later release to apply the upstream patch.
  • Avoid executing pack or unpack functions with templates derived from untrusted input; if such input must be processed, validate repeat counts before invocation.
  • Implement stricter input sanitization or replace vulnerable pack/unpack usage in critical code paths with safer alternatives when feasible.

Generated by OpenCVE AI on July 31, 2026 at 11:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Shay
Shay perl
Vendors & Products Shay
Shay perl

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.
Title Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Weaknesses CWE-125
CWE-190
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-14T13:34:42.360Z

Reserved: 2026-06-24T13:09:26.322Z

Link: CVE-2026-57432

cve-icon Vulnrichment

Updated: 2026-07-14T13:34:35.440Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses