{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-107373", "assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e", "state": "PUBLISHED", "assignerShortName": "CPANSec", "dateReserved": "2026-10-07T21:01:49.472Z", "datePublished": "2026-10-10T12:44:08.099Z", "dateUpdated": "2026-10-10T12:44:08.099Z" }, "containers": { "cna": { "affected": [ { "collectionURL": "https://cpan.org/modules", "defaultStatus": "unaffected", "modules": [ "ExtUtils::Typemaps::STL::String" ], "packageName": "ExtUtils-Typemaps-Default", "packageURL": "pkg:cpan/ExtUtils-Typemaps-Default", "programFiles": [ "lib/ExtUtils/Typemaps/STL/String.pm" ], "repo": "https://github.com/tsee/extutils-typemap-default", "versions": [ { "lessThan": "1.06", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "value": "ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.\n\nThe typemap uses\n\n $var = std::string( SvPV_nolen($arg), SvCUR($arg) )\n\nHowever, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.\n\nWhen $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault." } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e", "shortName": "CPANSec", "dateUpdated": "2026-10-10T12:44:08.099Z" }, "references": [ { "tags": [ "release-notes" ], "url": "https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes" }, { "url": "https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d" }, { "tags": [ "issue-tracking" ], "url": "https://rt.cpan.org/Public/Bug/Display.html?id=94110" }, { "tags": [ "related" ], "url": "https://www.cve.org/CVERecord?id=CVE-2026-80490" } ], "solutions": [ { "lang": "en", "value": "Upgrade to ExtUtils::Typemaps::Default version 1.06 or later.\n\nRebuild any modules that use ExtUtils::Typemaps::Default as part of their build process." } ], "source": { "discovery": "UNKNOWN" }, "timeline": [ { "lang": "en", "time": "2014-03-22T00:00:00.000Z", "value": "Issue reported in bugtracker for ExtUtils::Typemaps::Default version 1.05." }, { "lang": "en", "time": "2014-06-10T00:00:00.000Z", "value": "Fix committed to the repository. Bugtracker issue closed." }, { "lang": "en", "time": "2026-09-30T00:00:00.000Z", "value": "Issue reported to CPANSec." }, { "lang": "en", "time": "2026-10-08T00:00:00.000Z", "value": "ExtUtils::Typemaps::Default version 1.06 released with a fix." } ], "title": "ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument", "workarounds": [ { "lang": "en", "value": "For deployments that cannot be upgraded, ensure that arguments passed to modules that use ExtUtils::Typemaps::Default are strngified." } ], "x_generator": { "engine": "cpansec-cna-tool 0.1" } } } }