CVE-2026-107373

critical

Description

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. The typemap uses $var = std::string( SvPV_nolen($arg), SvCUR($arg) ) However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first. When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.

References

https://www.cve.org/CVERecord?id=CVE-2026-80490

https://rt.cpan.org/Public/Bug/Display.html?id=94110

https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes

https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-96314

Details

Source: Mitre, NVD

Published: 2026-10-10

Updated: 2026-10-10

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Severity: Critical

EPSS

EPSS: 0.00187