PT-2026-109644 · Undefined · Undefined
CVE-2026-107373
·
Published
2026-10-10
·
Updated
2026-10-10
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T STD STRING typemap may read the SV length before stringifying the argument.
The typemap uses
$var = std::string( SvPV nolen($arg), SvCUR($arg) )
However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.
When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined