Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-59142

Gravedad:
Pendiente de análisis
Tipo:
CWE-125 Lectura fuera de límites
Fecha de publicación:
21/07/2026
Última modificación:
21/07/2026

Descripción

*** Pendiente de traducción *** Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy.<br /> <br /> The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. shm_str_copy does memcpy(dst, arena + off, len) with off and len read raw from the mmap&amp;#39;d segment and unbounded, on the each, keys, values, pop, shift, take, swap, drain and cursor paths. The get path bounds off and len separately and is not affected.<br /> <br /> A local peer that can write the backing file can leave the header valid while poisoning a record&amp;#39;s offset and length, so iterating or draining the map copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.

Impacto