Description
Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked.

The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. reqrep_recv_locked does memcpy(copy_buf, req_arena + arena_off, len) with arena_off and len read raw from the mmap'd segment and never bounded against the arena capacity (req_arena_cap).

A local peer that can write the backing file can leave the header valid while poisoning a request slot's offset and length, so receiving the request copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Data::ReqRep::Shared exists because the module copies data from a shared arena without checking that the provided offset and length stay within the arena capacity. A local attacker, if able to modify the backing file, can leave the header valid but set a request slot’s offset and length to values that extend beyond the arena limits, causing the process to read or copy data beyond the arena. Based on the description, this out-of-bounds read could potentially expose arbitrary memory contents or lead to a crash, but the exact impact is not stated explicitly in the CVE text.

Affected Systems

All installations of EGOR:Data::ReqRep::Shared prior to version 0.05 on Perl systems are vulnerable. The vulnerability applies to the module’s shared memory handling, affecting any process that uses reqrep_recv_locked to receive requests.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a low but non‑zero exploitation probability in typical environments. Exploitation requires local write access to the shared arena backing file; therefore the attack vector is local. The CVSS score of 9.1 highlights a high severity impact; based on the description, an attacker could read arbitrary memory or cause the process to crash, but the CVE text does not detail the specific data leakage or denial‑of‑service outcomes, so those results are inferred.

Generated by OpenCVE AI on August 4, 2026 at 05:32 UTC.

Remediation

Vendor Solution

Upgrade to Data::ReqRep::Shared 0.05 or later, which bounds the arena offset and length against the arena capacity before the copy.


Vendor Workaround

For deployments that cannot upgrade to 0.05, place the backing file in a directory writable only by the owning user, so a local peer cannot tamper with the segment contents the read path trusts.


OpenCVE Recommended Actions

  • Upgrade to Data::ReqRep::Shared 0.05 or later, which bounds the arena offset and length before copying.
  • If an upgrade is not immediately possible, locate the backing file in a directory that is writable only by the owning user; this prevents a local peer from tampering with the segment contents that the read path trusts.
  • Ensure that the backing file and its containing directory have permissions that deny write access to non‑privileged users, limiting the ability of local peers to modify arena contents.

Generated by OpenCVE AI on August 4, 2026 at 05:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Egor
Egor data::reqrep::shared
Vendors & Products Egor
Egor data::reqrep::shared

Tue, 21 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. reqrep_recv_locked does memcpy(copy_buf, req_arena + arena_off, len) with arena_off and len read raw from the mmap'd segment and never bounded against the arena capacity (req_arena_cap). A local peer that can write the backing file can leave the header valid while poisoning a request slot's offset and length, so receiving the request copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.
Title Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked
Weaknesses CWE-125
References

Subscriptions

Egor Data::reqrep::shared
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-22T19:16:27.039Z

Reserved: 2026-07-02T16:24:17.912Z

Link: CVE-2026-59139

cve-icon Vulnrichment

Updated: 2026-07-22T19:16:05.832Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses