# CVE-2026-8376

## Summary

- **CVE ID:** CVE-2026-8376
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
- **CWE:** CWE-680
- **Published:** May 25, 2026
- **Last Modified:** Sep 8, 2026

## Description

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.

Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.

A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.

## Affected Products

- Unknown product (0)
- Unknown product (5.41.0)
- Unknown product (5.43.0)
- SHAY — perl (0)

## References

- [CNA](https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch)
- [CVE](http://www.openwall.com/lists/oss-security/2026/05/26/1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 37.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._