CVE-2026-12087
ADVISORY - debianSummary
Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.
- libsocket-perl 2.041-1 (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146063) [trixie] - libsocket-perl 2.038-1+deb13u1 [bookworm] - libsocket-perl (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source()) [bullseye] - libsocket-perl (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source()) [experimental] - perl 5.44.0-1
- perl 5.42.3-1 (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140152) [trixie] - perl 5.40.1-6+deb13u1 https://lists.security.metacpan.org/cve-announce/msg/41020451/ Fixed by: https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb (v5.43.11)
Debian
-
| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| debian/perl | deb | debian | 12 | >0 | Not yet available |
| debian/libsocket-perl | deb | debian | 14 | <2.041-1 | 2.041-1 |
| debian/libsocket-perl | deb | debian | unstable | <2.041-1 | 2.041-1 |
| debian/libsocket-perl | deb | debian | 13 | <2.038-1+deb13u1 | 2.038-1+deb13u1 |
| debian/libsocket-perl | deb | debian | 12 | >0 | Not yet available |
| debian/perl | deb | debian | 14 | <5.42.3-1 | 5.42.3-1 |
| debian/perl | deb | debian | 13 | <5.40.1-6+deb13u1 | 5.40.1-6+deb13u1 |
| debian/perl | deb | debian | unstable | <5.42.3-1 | 5.42.3-1 |
Severity and metrics
No CVSS data available from this advisory.
NIST
CVSS SCORE
9.1criticalUbuntu
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AlowRed Hat
3.9