PT-2026-98334 · Cpan · Xs::Parse::Infix

·

CVE-2026-85644

·

Published

2026-09-23

·

Updated

2026-09-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions XS::Parse::Infix versions 0.40 through 0.49
Description A flaw exists in the wrapper function generated for list-associative infix operators. The function uses SvRV() instead of SvROK() to check if arguments are array references. Because SvRV() reads a union slot that only holds a referent when SvROK(sv) is true, the guard fails to validate the reference. For integers (IV) or numbers (NV), this slot contains the number itself, leading SvRV() to return the caller's value and SvTYPE() to dereference it at offset 12, typically resulting in a segmentation fault. If an application processes decoded input, such as JSON, an attacker can provide a number to control the address the interpreter dereferences. A crafted string with 0x0b at byte 12 can bypass the guard, allowing the buffer to be treated as an array value (AV) head, where bytes 16-23 are interpreted as AvARRAY and pushed onto the Perl stack as live scalar values (SVs).
Recommendations Update XS::Parse::Infix to version 0.50.0 or later.

Fix

Out of bounds Read

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85644
OPENSUSE-SU-2026:11863-1

Affected Products

Xs::Parse::Infix