← Πίσω στην αναζήτηση CVE

CVE-2026-59142

Data::HashMap::Shared

Περιγραφή

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. shm_str_copy does memcpy(dst, arena + off, len) with off and len read raw from the mmap-d segment and unbounded, on the each, keys, values, pop, shift, take, swap, drain and cursor paths. The get path bounds off and len separately and is not affected. A local peer that can write the backing file can leave the header valid while poisoning a record-s offset and length, so iterating or draining the map copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.

CVSS 9.1EPSS 0.337%Κίνδυνος 0.94
Προβολή πηγής
Δημοσίευση
2026-07-21 19:17:11
Επηρεαζόμενες εκδόσεις
<0.14
Τύπος
Βιβλιοθήκη
Τελευταία τροποποίηση
2026-07-22 20:17:02
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H