GHSA-g3mm-4ggm-mrv5unknown
ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the...
🔗 CVE IDs covered (1)
📋 Description
ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.
The typemap uses
$var = std::string( SvPV_nolen($arg), SvCUR($arg) )
However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.
When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-107373
- https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d
- https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes
- https://rt.cpan.org/Public/Bug/Display.html?id=94110
- https://www.cve.org/CVERecord?id=CVE-2026-80490
- https://github.com/advisories/GHSA-g3mm-4ggm-mrv5