Socket versions before 2.041 for Perl have an out-of-bounds heap read.
In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.
Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade perl-SocketUpgrade perl-Socket-debuginfoUpgrade perl-Socket-debugsourceUpgrade perl-Socket-tests | Sep 30, 2026 | Jun 15, 2026 |
| Debian | — | Upgrade perlUpgrade libsocket-perl | Sep 21, 2026 | Jun 15, 2026 |
| Ibm Aix | — | Apply the fix or workaround for aix_vios_advisory | Aug 16, 2026 | Aug 14, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 15, 2026 |
| Ubuntu | — | Upgrade perl-baseUpgrade perl-modules-5.26 (Ubuntu Pro)Upgrade perlUpgrade libperl5.40Upgrade libperl5.34Upgrade perl-modules-5.22 (Ubuntu Pro)Upgrade perl-modules-5.30 (Ubuntu Pro)Upgrade libperl5.26 (Ubuntu Pro)Upgrade perl-modules-5.38Upgrade perl-modules-5.34Upgrade perl-base (Ubuntu Pro)Upgrade perl-modules (Ubuntu Pro)Upgrade libperl5.22 (Ubuntu Pro)Upgrade libperl5.30 (Ubuntu Pro)Upgrade perl-modules-5.40Upgrade libperl5.18 (Ubuntu Pro) | Aug 26, 2026 | Aug 25, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 23, 2026 | Jun 15, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub