CVE-2026-12087

ADVISORY - debian

Summary

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.


EPSS Score: 0.00374 (0.309)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Out-of-bounds Read

Buffer Access with Incorrect Length Value

ADVISORY - redhat

Out-of-bounds Read


Debian

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/perldebdebian12>0Not yet available
debian/libsocket-perldebdebian14<2.041-12.041-1
debian/libsocket-perldebdebianunstable<2.041-12.041-1
debian/libsocket-perldebdebian13<2.038-1+deb13u12.038-1+deb13u1
debian/libsocket-perldebdebian12>0Not yet available
debian/perldebdebian14<5.42.3-15.42.3-1
debian/perldebdebian13<5.40.1-6+deb13u15.40.1-6+deb13u1
debian/perldebdebianunstable<5.42.3-15.42.3-1

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

9.1critical

Ubuntu

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Amazon

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

Red Hat

CREATED

UPDATED

EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.3medium