Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.
retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.
A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade perl | Sep 21, 2026 | Jul 13, 2026 |
| Ubuntu | — | Upgrade libperl5.34Upgrade perlUpgrade perl-baseUpgrade perl-modules-5.30 (Ubuntu Pro)Upgrade libperl5.22 (Ubuntu Pro)Upgrade libperl5.40Upgrade perl-modules-5.26 (Ubuntu Pro)Upgrade libperl5.18 (Ubuntu Pro)Upgrade perl-modules-5.34Upgrade perl-base (Ubuntu Pro)Upgrade perl-modules-5.22 (Ubuntu Pro)Upgrade perl-modules-5.38Upgrade perl-modules-5.40Upgrade libperl5.26 (Ubuntu Pro)Upgrade perl-modules (Ubuntu Pro)Upgrade libperl5.30 (Ubuntu Pro) | Aug 26, 2026 | Aug 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub