{"id":"CVE-2026-57432","summary":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack","details":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.","modified":"2026-09-10T08:21:23.137944Z","published":"2026-07-13T15:38:20.728Z","related":["SUSE-SU-2026:22847-1","SUSE-SU-2026:22929-1","SUSE-SU-2026:23008-1","SUSE-SU-2026:23075-1","SUSE-SU-2026:3540-1","SUSE-SU-2026:3558-1","openSUSE-SU-2026:21411-1"],"database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-125","CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57432.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/13/6"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57432.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432"},{"type":"FIX","url":"https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch"},{"type":"FIX","url":"https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch"},{"type":"PACKAGE","url":"https://github.com/Perl/perl5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/perl/perl5","events":[{"introduced":"0"},{"fixed":"40754edc72dd3e513d758153c0e2f0215897740e"},{"fixed":"5f7eb6bbbe0510964e3fb1d6bb691e5445913e55"}],"database_specific":{"cpe":"cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"5.43.10"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v5.43.10","v5.43.9","v5.43.8","v5.42.0","v5.43.6","v5.43.2","v5.43.1","v5.43.0","v5.42.0-RC3","v5.42.0-RC2","v5.42.0-RC1","v5.41.13","v5.41.12","v5.41.11","v5.41.10","v5.41.9","v5.41.8","v5.41.7","v5.41.5","v5.41.4","v5.41.3","v5.40.0","v5.41.2","v5.41.1","v5.41.0","v5.40.0-RC2","v5.40.0-RC1","v5.39.8","v5.39.7","v5.39.5","v5.39.4","v5.38.0","v5.39.3","v5.39.1","v5.39.0","v5.38.0-RC2","v5.38.0-RC1","v5.37.11","v5.37.10","v5.37.9","v5.37.7","v5.37.6","v5.37.5","v5.37.4","v5.37.3","v5.37.2","v5.37.1","v5.36.0","v5.37.0","v5.36.0-RC3","v5.35.11","v5.35.10","v5.34.0","v5.35.9","v5.35.8","v5.35.6","v5.35.5","v5.35.3","v5.35.0","v5.34.0-RC2","v5.34.0-RC1","v5.33.9","v5.33.8","v5.33.7","v5.32.0","v5.33.4","v5.33.3","v5.33.2","v5.33.1","v5.33.0","v5.32.0-RC1","v5.31.11","v5.31.7","v5.31.5","v5.30.0","v5.31.4","v5.31.3","v5.31.2","v5.31.1","v5.31.0","v5.30.0-RC2","v5.30.0-RC1","v5.29.10","v5.29.9","v5.29.8","v5.29.7","v5.29.6","v5.29.5","v5.28.0","v5.29.1","v5.29.0","v5.28.0-RC4","v5.28.0-RC3","v5.28.0-RC2","v5.28.0-RC1","v5.27.11","v5.27.10","v5.27.8","v5.27.7","v5.27.6","v5.27.5","v5.27.3","v5.26.0","v5.27.0","v5.26.0-RC2","v5.25.11","v5.25.9","v5.25.7","v5.25.5","v5.25.4","v5.25.3","v5.24.0","v5.25.2","v5.25.0","v5.24.0-RC5","v5.24.0-RC4","v5.24.0-RC3","v5.24.0-RC2","v5.24.0-RC1","v5.23.7","v5.23.6","v5.23.4","v5.23.3","if-0.0605","v5.23.2","v5.23.1","v5.23.0","v5.22.0","v5.22.0-RC2","v5.22.0-RC1","v5.21.11","if-0.0604","v5.21.10","v5.21.9","v5.21.8","v5.21.6","v5.21.5","v5.21.4","v5.21.1","v5.21.0","v5.20.0","v5.20.0-RC1","v5.19.11","v5.19.7","v5.19.5","v5.19.3","v5.19.2","if-0.0603","v5.19.1","v5.18.0","v5.19.0","v5.18.0-RC4","v5.18.0-RC3","v5.18.0-RC2","v5.18.0-RC1","v5.17.9","v5.17.8","v5.17.7.0","v5.17.7","v5.17.6","v5.17.4","v5.17.2","v5.17.0","v5.16.0","v5.16.0-RC2","v5.16.0-RC1","v5.15.9","v5.15.5","v5.15.4","v5.15.3","v5.15.2","v5.15.1","v5.15.0","v5.14.0","v5.14.0-RC3","v5.14.0-RC2","v5.14.0-RC1","v5.13.11","v5.13.10","v5.13.9","v5.13.8","v5.13.7","v5.13.6","v5.13.5","v5.13.4","v5.13.3","v5.13.2","v5.13.1","v5.12.0","v5.13.0","v5.12.0-RC5","v5.12.0-RC4","v5.12.0-RC3","v5.12.0-RC2","v5.12.0-RC1","v5.12.0-RC0","v5.11.5","v5.11.4","v5.11.3","v5.11.1","v5.11.0","GitLive-blead","v5.10.0","perl-5.9.5","perl-5.9.4","perl-5.9.3","perl-5.9.2","perl-5.9.1","perl-5.9.0","perl-5.8.0","perl-5.7.3","perl-5.7.2","perl-5.7.1","perl-5.7.0","perl-5.6.0","perl-5.005","perl-5.003","perl-5.002_01","perl-5.002","perl-5.001n","perl-5.001","perl-5.000o","perl-5.000","perl-5a9","perl-5a2","perl-4.0.36","perl-4.0.00","perl-3.044","perl-3.000","perl-2.0","perl-1.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["201862577156805249707604620553032475083","81551603836204907529493426019519997190","156059514884981184402847233614461914785","94570857617259539047657028996045109747","97659039899658249284388648446262969742","151926469226482392204243810170594964244","272884511119481635539903956287963567103","222344025253663211649859476963107431631","236897441416428657598893805152526053149"],"threshold":0.9},"id":"CVE-2026-57432-567f9e91","signature_type":"Line","signature_version":"v1","source":"https://github.com/perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e","target":{"file":"pp_pack.c"}},{"signature_version":"v1","source":"https://github.com/perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55","target":{"file":"pp_pack.c","function":"S_measure_struct"},"deprecated":false,"digest":{"function_hash":"25072063771270511445671413082026489545","length":1564},"id":"CVE-2026-57432-7dacdb06","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55","target":{"file":"pp_pack.c"},"deprecated":false,"digest":{"line_hashes":["29903863876335406943443366041508711239","69081311608836401256429370573162305475","82901968090413512737454453188025013684","188272959908224046124473974834687995312"],"threshold":0.9},"id":"CVE-2026-57432-a8660b53"},{"deprecated":false,"digest":{"length":1714,"function_hash":"234785783132956280921451274473264633819"},"id":"CVE-2026-57432-b85c915f","signature_type":"Function","signature_version":"v1","source":"https://github.com/perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e","target":{"file":"pp_pack.c","function":"S_measure_struct"}}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-57432.json","vanir_signatures_modified":"2026-09-10T08:21:23Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}