Description
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.

Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.

A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.
Published: 2026-05-25
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Heap Buffer Overflow
Action: Upgrade Perl
AI Analysis

Impact

A stack heap buffer overflow is triggered in 32‑bit Perl builds when compiling a regular expression that contains a repeated fixed string with a large minimum count. The regex compiler calculates the required buffer size in characters rather than bytes, causing the signed size computation to overflow and resulting in a smaller allocation. The subsequent copy then writes past the end of the buffer, corrupting heap memory. The flaw can allow an attacker to overwrite critical heap data, possibly leading to arbitrary code execution or a denial‑of‑service crash.

Affected Systems

This vulnerability affects all 32‑bit Perl installations running versions prior to 5.40.5‑RC1, any 5.41.x release before 5.42.3‑RC1, and any 5.43.x release before 5.43.11. 64‑bit builds are not known to be affected. The recommended remedy is to upgrade to Perl 5.40.5, 5.42.3, 5.44.0 or later, or to apply the upstream patch provided in the advisory.

Risk and Exploitability

The CVSS score of 7.3 indicates a moderate‑to‑high severity flaw, and the EPSS score of less than 1 % shows a low likelihood of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can trigger the overflow by supplying a specially crafted regular expression from untrusted input to a 32‑bit Perl application, which can then lead to heap corruption and potential code execution or crash.

Generated by OpenCVE AI on September 10, 2026 at 05:55 UTC.

Remediation

Vendor Solution

Upgrade to Perl 5.40.5, 5.42.3 or 5.44.0 or later, or apply the upstream patch.


Vendor Workaround

On 32-bit perl builds, avoid compiling regular expressions from untrusted input until a fixed release is installed.


OpenCVE Recommended Actions

  • Upgrade all 32‑bit Perl installations to a fixed release such as 5.40.5, 5.42.3, 5.44.0 or newer.
  • If an upgrade cannot be performed immediately, apply the upstream patch available from the provided commit URL.
  • Until the upgrade or patch is in place, do not compile user‑supplied or untrusted regular expressions on 32‑bit builds; validate or reject such input.

Generated by OpenCVE AI on September 10, 2026 at 05:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8467-1 Perl vulnerabilities
Ubuntu USN Ubuntu USN USN-8467-2 Perl vulnerabilities
History

Tue, 08 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time. Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.
Title Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds

Wed, 27 May 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Wed, 27 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Perl
Perl perl
CPEs cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*
Vendors & Products Perl
Perl perl
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 26 May 2026 13:45:00 +0000

Type Values Removed Values Added
References

Tue, 26 May 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Shay
Shay perl
Vendors & Products Shay
Shay perl

Tue, 26 May 2026 00:15:00 +0000

Type Values Removed Values Added
Description Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.
Title Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
Weaknesses CWE-680
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-08T21:33:36.127Z

Reserved: 2026-05-12T08:15:41.456Z

Link: CVE-2026-8376

cve-icon Vulnrichment

Updated: 2026-05-26T03:06:00.816Z

cve-icon NVD

Status : Modified

Published: 2026-05-26T00:16:57.150

Modified: 2026-09-08T22:19:18.373

Link: CVE-2026-8376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T06:00:08Z

Weaknesses
  • CWE-680

    Integer Overflow to Buffer Overflow