Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <arI3XrCf7hgIbFlM@pjcj.com>
Date: Tue, 22 Sep 2026 10:09:22 +0200
From: Paul Johnson <paul@...j.net>
To: cve-announce@...urity.metacpan.org, oss-security@...ts.openwall.com
Subject: CVE-2026-87082: Net::IDN::Punycode versions before 2.590 for Perl
 hang, crash or return a wrong label via unvalidated malformed UTF-8 in
 encode_punycode

========================================================================
CVE-2026-87082                                       CPAN Security Group
========================================================================

        CVE ID:  CVE-2026-87082

  Distribution:  Net-IDN-Encode
      Versions:  before 2.590
      MetaCPAN:  https://metacpan.org/dist/Net-IDN-Encode
      VCS Repo:  https://github.com/robrwo/Net-IDN-Encode


Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return
a wrong label via unvalidated malformed UTF-8 in encode_punycode

Description
-----------
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return
a wrong label via unvalidated malformed UTF-8 in encode_punycode.

Neither backend checks that its input is well-formed UTF-8, so a string
with the UTF-8 flag set over malformed bytes, as the :utf8 PerlIO layer
produces from any malformed input, reaches the encoder unchecked. On
perl 5.32 and later the XS backend reports a malformed sequence with a
length of `(STRLEN)-1`, so the scan steps back one byte instead of
forward and never ends. On earlier perls the XS returns a valid label
for a different name. The pure-Perl backend runs a regex over the
flagged string. Depending on the bytes, it aborts with SIGBUS on perl
5.28 and later, dies with a panic, or returns a wrong label.

The documented conversion functions match the label against Unicode
properties first and that match dies on such a string, so only a direct
call to encode_punycode reaches the defect. The decoder is not
affected.

A direct caller encoding attacker-supplied bytes hangs, crashes or gets
a label for a name the input never held.

Problem types
-------------
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
- CWE-1286 Improper Validation of Syntactic Correctness of Input

Solutions
---------
Upgrade to Net-IDN-Encode 2.590-TRIAL or later.

References
----------
https://metacpan.org/release/PJCJ/Net-IDN-Encode-2.590-TRIAL/changes
https://github.com/robrwo/Net-IDN-Encode/commit/0918fb4a951ed5f4494c4cf202419c2842507ea4.patch
https://github.com/robrwo/Net-IDN-Encode/commit/59dc7f2c605a897bcbfe0ac5eb2b8dbe6792348d.patch
https://github.com/robrwo/Net-IDN-Encode/commit/accb6df57ad107ec0c4bfb27b21551eed97c700e.patch
https://github.com/robrwo/Net-IDN-Encode/commit/572af0183b3a6294e22c6b509268da09697cf77d.patch

-- 
Paul Johnson - paul@...j.net

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.