PT-2026-57823 · Perl+3 · Perl+3

CVE-2026-57432

·

Published

2026-07-13

·

Updated

2026-09-09

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Perl versions prior to 5.43.11
Description An integer overflow exists in the S measure struct() function. This occurs because the function calculates the total size by adding each item's size multiplied by its repeat count without performing an overflow check. A large repeat count in a pack or unpack template can cause the signed SSize t total to wrap to a negative value. Consequently, the @, X, and x position codes use a signed length comparison that allows the buffer pointer to advance out of bounds. If a template is derived from untrusted input, this can result in an out-of-bounds heap read, allowing memory to be read past the buffer and returned to the caller.
Recommendations Update Perl to version 5.43.11 or later.

Exploit

Fix

DoS

Out of bounds Read

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92297
CVE-2026-57432
ECHO-AF51-DF70-C8C4
OESA-2026-3224
OPENSUSE-SU-2026:21411-1
RHSA-2026:39997
SUSE-SU-2026:22847-1
SUSE-SU-2026:22929-1
SUSE-SU-2026:23008-1
SUSE-SU-2026:23075-1
SUSE-SU-2026:3540-1
SUSE-SU-2026:3558-1
USN-8675-1
USN-8675-2
USN-8684-1

Affected Products

Linuxmint
Perl
Red Os
Ubuntu