Description
ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.

The typemap uses

$var = std::string( SvPV_nolen($arg), SvCUR($arg) )

However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.

When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.
Published: 2026-10-10
Score: n/a
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to ExtUtils::Typemaps::Default version 1.06 or later. Rebuild any modules that use ExtUtils::Typemaps::Default as part of their build process.


Vendor Workaround

For deployments that cannot be upgraded, ensure that arguments passed to modules that use ExtUtils::Typemaps::Default are strngified.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. The typemap uses $var = std::string( SvPV_nolen($arg), SvCUR($arg) ) However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first. When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.
Title ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument
Weaknesses CWE-125
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-10-10T12:44:08.099Z

Reserved: 2026-10-07T21:01:49.472Z

Link: CVE-2026-107373

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T13:17:31.253

Modified: 2026-10-10T13:17:31.253

Link: CVE-2026-107373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses