CVE-2026-107373
Las versiones de ExtUtils::Typemaps::STL::String anteriores a la 1.06 para el mapa de tipos T_STD_STRING de Perl pueden leer la longitud del SV antes de convertir el argumento a cadena.
El mapa de tipos utiliza
Sin embargo, el orden de evaluación de los argumentos de C++ no está especificado, y algunos compiladores pueden generar código que evalúa primero SvCUR($arg).
Cuando $arg no es una cadena (por ejemplo, un entero, número o una referencia), entonces SvCUR devolverá un valor inválido, y el programa puede abortar o sufrir una violación de segmentación.
Detalles técnicos trazas, registros y código del informe original
$var = std::string( SvPV_nolen($arg), SvCUR($arg) )
Traducción automática del texto original de NVD (en inglés).
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
FIRST aún no ha puntuado esta CVE (habitual en CVEs muy recientes o rechazadas).
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-125
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-107373",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"affectedData": [
{
"repo": "https://github.com/tsee/extutils-typemap-default",
"modules": [
"ExtUtils::Typemaps::STL::String"
],
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.06",
"versionType": "custom"
}
],
"packageURL": "pkg:cpan/ExtUtils-Typemaps-Default",
"packageName": "ExtUtils-Typemaps-Default",
"programFiles": [
"lib/ExtUtils/Typemaps/STL/String.pm"
],
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-10-10T13:17:31.253",
"references": [
{
"url": "https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://rt.cpan.org/Public/Bug/Display.html?id=94110",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80490",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}
],
"vulnStatus": "Received",
"weaknesses": [
{
"type": "Secondary",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.\n\nThe typemap uses\n\n $var = std::string( SvPV_nolen($arg), SvCUR($arg) )\n\nHowever, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.\n\nWhen $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault."
}
],
"lastModified": "2026-10-10T13:17:31.253",
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}