« Volver al listado

CVE-2026-107373

Estado: RecibidaSin puntuar—

Las versiones de ExtUtils::Typemaps::STL::String anteriores a la 1.06 para el mapa de tipos T_STD_STRING de Perl pueden leer la longitud del SV antes de convertir el argumento a cadena.

El mapa de tipos utiliza

Sin embargo, el orden de evaluación de los argumentos de C++ no está especificado, y algunos compiladores pueden generar código que evalúa primero SvCUR($arg).

Cuando $arg no es una cadena (por ejemplo, un entero, número o una referencia), entonces SvCUR devolverá un valor inválido, y el programa puede abortar o sufrir una violación de segmentación.

Detalles técnicos trazas, registros y código del informe original
    $var = std::string( SvPV_nolen($arg), SvCUR($arg) )

Traducción automática del texto original de NVD (en inglés).

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

FIRST aún no ha puntuado esta CVE (habitual en CVEs muy recientes o rechazadas).

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-107373",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://github.com/tsee/extutils-typemap-default",
          "modules": [
            "ExtUtils::Typemaps::STL::String"
          ],
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.06",
              "versionType": "custom"
            }
          ],
          "packageURL": "pkg:cpan/ExtUtils-Typemaps-Default",
          "packageName": "ExtUtils-Typemaps-Default",
          "programFiles": [
            "lib/ExtUtils/Typemaps/STL/String.pm"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-10-10T13:17:31.253",
  "references": [
    {
      "url": "https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://rt.cpan.org/Public/Bug/Display.html?id=94110",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80490",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    }
  ],
  "vulnStatus": "Received",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.\n\nThe typemap uses\n\n    $var = std::string( SvPV_nolen($arg), SvCUR($arg) )\n\nHowever, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.\n\nWhen $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault."
    }
  ],
  "lastModified": "2026-10-10T13:17:31.253",
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}