|
|
Message-ID: <arI3XrCf7hgIbFlM@pjcj.com>
Date: Tue, 22 Sep 2026 10:09:22 +0200
From: Paul Johnson <paul@...j.net>
To: cve-announce@...urity.metacpan.org, oss-security@...ts.openwall.com
Subject: CVE-2026-87082: Net::IDN::Punycode versions before 2.590 for Perl
hang, crash or return a wrong label via unvalidated malformed UTF-8 in
encode_punycode
========================================================================
CVE-2026-87082 CPAN Security Group
========================================================================
CVE ID: CVE-2026-87082
Distribution: Net-IDN-Encode
Versions: before 2.590
MetaCPAN: https://metacpan.org/dist/Net-IDN-Encode
VCS Repo: https://github.com/robrwo/Net-IDN-Encode
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return
a wrong label via unvalidated malformed UTF-8 in encode_punycode
Description
-----------
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return
a wrong label via unvalidated malformed UTF-8 in encode_punycode.
Neither backend checks that its input is well-formed UTF-8, so a string
with the UTF-8 flag set over malformed bytes, as the :utf8 PerlIO layer
produces from any malformed input, reaches the encoder unchecked. On
perl 5.32 and later the XS backend reports a malformed sequence with a
length of `(STRLEN)-1`, so the scan steps back one byte instead of
forward and never ends. On earlier perls the XS returns a valid label
for a different name. The pure-Perl backend runs a regex over the
flagged string. Depending on the bytes, it aborts with SIGBUS on perl
5.28 and later, dies with a panic, or returns a wrong label.
The documented conversion functions match the label against Unicode
properties first and that match dies on such a string, so only a direct
call to encode_punycode reaches the defect. The decoder is not
affected.
A direct caller encoding attacker-supplied bytes hangs, crashes or gets
a label for a name the input never held.
Problem types
-------------
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
- CWE-1286 Improper Validation of Syntactic Correctness of Input
Solutions
---------
Upgrade to Net-IDN-Encode 2.590-TRIAL or later.
References
----------
https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/changes
https://github.com/robrwo/Net-IDN-Encode/commit/0918fb4a951ed5f4494c4cf202419c2842507ea4.patch
https://github.com/robrwo/Net-IDN-Encode/commit/59dc7f2c605a897bcbfe0ac5eb2b8dbe6792348d.patch
https://github.com/robrwo/Net-IDN-Encode/commit/accb6df57ad107ec0c4bfb27b21551eed97c700e.patch
https://github.com/robrwo/Net-IDN-Encode/commit/572af0183b3a6294e22c6b509268da09697cf77d.patch
--
Paul Johnson - paul@...j.net
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.