Description
Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked.

The attach-time validator rb_validate_header checks the header scalars and region layout against the file size, but does not validate the bucket contents it then trusts. rb_contains_locked forms a container pointer as pool + container_off * 8192 from a raw file-stored offset and then searches over a file-stored cardinality, neither bounded against the container pool capacity or the fixed 8192-byte slot size.

A local peer that can write the backing file can leave the header valid while poisoning a bucket, so the next membership query dereferences a file-controlled wild pointer and scans a file-controlled count, reading adjacent memory or crashing the process.
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Data::RoaringBitmap::Shared versions before 0.02 contain an unvalidated container offset and cardinality check in rb_contains_locked, which allows an out-of-bounds read. Dereferencing a file‑controlled pointer can reveal adjacent memory contents or crash the process, a manifestation of the out-of-bounds read weakness (CWE-125). The vulnerability can lead to inadvertent data leakage or denial of service if an attacker gains access to the shared backing file.

Affected Systems

The affected product is Data::RoaringBitmap::Shared by EGOR, any version prior to 0.02. The issue is tied to the shared memory file used for exploding bitmap data in Perl scripts.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests low exploitation probability. This vulnerability is not listed in CISA KEV. Exploitation requires local write access to the shared backing file, so a local peer with sufficient privileges can tamper with the bucket contents to trigger the out-of-bounds read. The lack of bounds checks in the container pointer construction makes the attack straightforward once the arbitrary write condition is satisfied.

Generated by OpenCVE AI on August 3, 2026 at 00:31 UTC.

Remediation

Vendor Solution

Upgrade to Data::RoaringBitmap::Shared 0.02 or later, which clamps an out-of-range container offset to the empty sentinel and caps the cardinality at the slot capacity.


Vendor Workaround

For deployments that cannot upgrade to 0.02, place the backing file in a directory writable only by the owning user, so a local peer cannot tamper with the buckets the query path reads.


OpenCVE Recommended Actions

  • Upgrade to Data::RoaringBitmap::Shared 0.02 or later.
  • Place the backing file in a directory writable only by the owning user to prevent local peers from tampering with buckets.
  • Ensure the backing file itself is writable only by the owning user so that no other users can modify it.

Generated by OpenCVE AI on August 3, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Egor
Egor data::roaringbitmap::shared
Vendors & Products Egor
Egor data::roaringbitmap::shared

Thu, 23 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the header scalars and region layout against the file size, but does not validate the bucket contents it then trusts. rb_contains_locked forms a container pointer as pool + container_off * 8192 from a raw file-stored offset and then searches over a file-stored cardinality, neither bounded against the container pool capacity or the fixed 8192-byte slot size. A local peer that can write the backing file can leave the header valid while poisoning a bucket, so the next membership query dereferences a file-controlled wild pointer and scans a file-controlled count, reading adjacent memory or crashing the process.
Title Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked
Weaknesses CWE-125
References

Subscriptions

Egor Data::roaringbitmap::shared
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-23T12:14:48.600Z

Reserved: 2026-07-02T16:24:17.912Z

Link: CVE-2026-59143

cve-icon Vulnrichment

Updated: 2026-07-23T12:14:04.682Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:45:03Z

Weaknesses