CVE-2026-8376
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.44%
- CWE
- CWE-680
- Published
- 2026-05-25
- Last modified
- 2026-09-08
Affected products
- SHAY perl
Weakness type
Related vulnerabilities
- CVE-2026-81647 — Out-of-bounds read vulnerability in the graphics module....
- CVE-2026-19313 — Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution
- CVE-2026-70651 — libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick
- CVE-2026-19588 — Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow...
- CVE-2026-43627 — llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
- CVE-2026-55200 — libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
- CVE-2026-24928 — Out-of-bounds write vulnerability in the file system module....
- CVE-2026-25541 — Bytes is vulnerable to integer overflow in BytesMut::reserve