Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <273591a6-5b7e-4184-93a8-bc51961618ed@cpansec.org>
Date: Sat, 10 Oct 2026 13:46:45 +0100
From: Robert Rothenberg <rrwo@...nsec.org>
To: cve-announce@...urity.metacpan.org, oss-security@...ts.openwall.com
Subject: CVE-2026-107373: ExtUtils::Typemaps::STL::String versions before 1.06
 for Perl T_STD_STRING typemap may read the SV length before stringifying the
 argument

========================================================================
CVE-2026-107373                                      CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-107373

   Distribution:  ExtUtils-Typemaps-Default
       Versions:  before 1.06
       MetaCPAN: https://metacpan.org/dist/ExtUtils-Typemaps-Default
       VCS Repo:  https://github.com/tsee/extutils-typemap-default


ExtUtils::Typemaps::STL::String versions before 1.06 for Perl
T_STD_STRING typemap may read the SV length before stringifying the
argument

Description
-----------
ExtUtils::Typemaps::STL::String versions before 1.06 for Perl
T_STD_STRING typemap may read the SV length before stringifying the
argument.

The typemap uses

     $var = std::string( SvPV_nolen($arg), SvCUR($arg) )

However, evaluation order for C++ arguments is not specified, and some
compilers may produce code that evalutes SvCUR($arg) first.

When $arg is not a string (for example, an interger, number or a
reference) then SvCUR will return an invalid value, and the program may
abort or segfault.

Problem types
-------------
- CWE-125 Out-of-bounds Read

Workarounds
-----------
For deployments that cannot be upgraded, ensure that arguments passed
to modules that use ExtUtils::Typemaps::Default are strngified.

Solutions
---------
Upgrade to ExtUtils::Typemaps::Default version 1.06 or later.

Rebuild any modules that use ExtUtils::Typemaps::Default as part of
their build process.

References
----------
https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes
https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d
https://rt.cpan.org/Public/Bug/Display.html?id=94110
https://www.cve.org/CVERecord?id=CVE-2026-80490

Timeline
--------
- 2014-03-22: Issue reported in bugtracker for
   ExtUtils::Typemaps::Default version 1.05.
- 2014-06-10: Fix committed to the repository. Bugtracker issue closed.
- 2026-09-30: Issue reported to CPANSec.
- 2026-10-08: ExtUtils::Typemaps::Default version 1.06 released with a
   fix.



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.