Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.
S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.
A template derived from untrusted input can read heap memory past the buffer and return it to the caller.
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade perl | Sep 21, 2026 | Jul 13, 2026 |
| Redhat_linux | — | No solution exists | Aug 5, 2026 | Jul 13, 2026 |
| Ubuntu | — | Upgrade perl-baseUpgrade libperl5.18 (Ubuntu Pro)Upgrade libperl5.26 (Ubuntu Pro)Upgrade libperl5.40Upgrade perl-modules-5.40Upgrade perl-modules (Ubuntu Pro)Upgrade perl-modules-5.34Upgrade libperl5.34Upgrade perl-modules-5.26 (Ubuntu Pro)Upgrade perl-modules-5.30 (Ubuntu Pro)Upgrade perl-modules-5.22 (Ubuntu Pro)Upgrade libperl5.30 (Ubuntu Pro)Upgrade perl-base (Ubuntu Pro)Upgrade perl-modules-5.38Upgrade libperl5.22 (Ubuntu Pro)Upgrade perl | Aug 26, 2026 | Aug 25, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 10, 2026 | Jul 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub