GHSA-g3mm-4ggm-mrv5unknown

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the...

Published
October 10, 2026
Last Modified
October 10, 2026

🔗 CVE IDs covered (1)

📋 Description

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.

The typemap uses

$var = std::string( SvPV_nolen($arg), SvCUR($arg) )

However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.

When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.

🔗 References (6)