PT-2026-29223 · Unknown+1 · Sereal::Encoder+1

CVE-2024-14031

·

Publicado

2026-03-31

·

Atualizado

2026-07-25

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sereal::Encoder versions 4.000 through 4.009 002
Description Sereal::Encoder for Perl includes a vulnerable version of the Zstandard (zstd) library. A race condition exists in the one-pass compression functions of Zstandard versions prior to 1.3.8, potentially allowing an attacker to write bytes out of bounds when using an output buffer smaller than the recommended size.
Recommendations Update Sereal::Encoder to a version that includes Zstandard 1.3.8 or later.

Exploit

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-14031
GHSA-W77F-WV46-4VCX

Produtos afetados

Sereal::Encoder
Zstandard