Description
Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot.

The attach-time validator sph_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. sph_walk_cell reads entries[buckets[b]] and follows each entry's next link raw, and sph_alloc_slot writes through a file-stored free_head index, none bounded against the entry count (max_entries).

A local peer that can write the backing file can leave the header valid while poisoning the bucket chain and free list, so a query reads through an out-of-bounds bucket and next index and an insert writes through an out-of-bounds free-list head, corrupting memory or crashing the process.
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Data::SpatialHash::Shared versions before 0.02 allow an unvalidated bucket, link, and free-list index to be used in sph_walk_cell and sph_alloc_slot, resulting in out-of-bounds reads and writes across the backing file. The vulnerability arises because the header validator checks size but does not validate array contents, permitting an attacker to corrupt the bucket chain or free-list head. If an attacker can write to the backing file, they can trigger memory corruption or a crash. The weakness matches CWE-125 (Out‑of‑Bounds Read) and CWE-787 (Out‑of‑Bounds Write).

Affected Systems

All releases of EGOR Data::SpatialHash::Shared prior to version 0.02 are affected. Upgrading to 0.02 or later mitigates the issue. Products older than 0.02 lack the bounds checking that protects entry indices.

Risk and Exploitability

The CVSS score of 7.8 demonstrates a high severity level, while the EPSS score of less than 1% indicates limited exploitation likelihood at present. The flaw is not listed in the CISA KEV catalog. An attacker must have local write access to the shared file to manipulate bucket chains or free lists; thus the attack vector is local rather than remote. Once the file is tampered with, a read or write operation can trigger memory corruption or a crash. Given the low exploitation probability and local nature, the risk remains a high severity for affected environments, but practical exploitation would require a compromised local user.

Generated by OpenCVE AI on August 4, 2026 at 05:30 UTC.

Remediation

Vendor Solution

Upgrade to Data::SpatialHash::Shared 0.02 or later, which bounds every entry index against the entry count before dereferencing it.


Vendor Workaround

For deployments that cannot upgrade to 0.02, place the backing file in a directory writable only by the owning user, so a local peer cannot tamper with the bucket chain and free list.


OpenCVE Recommended Actions

  • Upgrade Data::SpatialHash::Shared to version 0.02 or later
  • Place the backing file in a directory that is writable only by the owning user to prevent other local peers from tampering
  • If upgrading is not immediately possible, monitor and restrict any local write access to the shared file until a patch is applied

Generated by OpenCVE AI on August 4, 2026 at 05:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Egor
Egor data::spatialhash::shared
Vendors & Products Egor
Egor data::spatialhash::shared

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator sph_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. sph_walk_cell reads entries[buckets[b]] and follows each entry's next link raw, and sph_alloc_slot writes through a file-stored free_head index, none bounded against the entry count (max_entries). A local peer that can write the backing file can leave the header valid while poisoning the bucket chain and free list, so a query reads through an out-of-bounds bucket and next index and an insert writes through an out-of-bounds free-list head, corrupting memory or crashing the process.
Title Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot
Weaknesses CWE-125
CWE-787
References

Subscriptions

Egor Data::spatialhash::shared
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-22T19:36:54.589Z

Reserved: 2026-07-02T16:24:17.913Z

Link: CVE-2026-59146

cve-icon Vulnrichment

Updated: 2026-07-22T19:36:04.892Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses