Back

CRITICAL

Storable versions before 3.05 for Perl has a stack overflow

Published Apr 21, 2026

Description

Storable versions before 3.05 for Perl has a stack overflow.

The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

Affected products

Remediation

Vendor solution

Upgrade to Storable version 3.05 or newer.

Red Hat statement

This is an Moderate denial of service flaw in perl-Storable. The vulnerability arises from incorrect handling of class name lengths during deserialization, which can lead to a stack overflow when processing specially crafted data. To exploit this vulnerability the attacker needs to trick the user to use a maliciously crafted data.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Apr 21, 2026
Updated Apr 21, 2026
Reserved Mar 28, 2026
CISA Vulnrichment
Updated Apr 21, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 21, 2026