CVE-2026-59142
Gravedad:
Pendiente de análisis
Tipo:
CWE-125
Lectura fuera de límites
Fecha de publicación:
21/07/2026
Última modificación:
21/07/2026
Descripción
*** Pendiente de traducción *** Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy.<br />
<br />
The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. shm_str_copy does memcpy(dst, arena + off, len) with off and len read raw from the mmap&#39;d segment and unbounded, on the each, keys, values, pop, shift, take, swap, drain and cursor paths. The get path bounds off and len separately and is not affected.<br />
<br />
A local peer that can write the backing file can leave the header valid while poisoning a record&#39;s offset and length, so iterating or draining the map copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.



