PT-2026-98334 · Cpan · Xs::Parse::Infix
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
XS::Parse::Infix versions 0.40 through 0.49
Description
A flaw exists in the wrapper function generated for list-associative infix operators. The function uses
SvRV() instead of SvROK() to check if arguments are array references. Because SvRV() reads a union slot that only holds a referent when SvROK(sv) is true, the guard fails to validate the reference. For integers (IV) or numbers (NV), this slot contains the number itself, leading SvRV() to return the caller's value and SvTYPE() to dereference it at offset 12, typically resulting in a segmentation fault. If an application processes decoded input, such as JSON, an attacker can provide a number to control the address the interpreter dereferences. A crafted string with 0x0b at byte 12 can bypass the guard, allowing the buffer to be treated as an array value (AV) head, where bytes 16-23 are interpreted as AvARRAY and pushed onto the Perl stack as live scalar values (SVs).Recommendations
Update XS::Parse::Infix to version 0.50.0 or later.
Fix
Out of bounds Read
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xs::Parse::Infix