CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers
Published May 28, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.80%
Description
CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers.
The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the buffer. Version 0.088 added the clamp to gcm_decrypt_verify, and 0.088_001 added it to the other three.
Any caller of an affected helper that forwards an attacker-controlled tag longer than the buffer can trigger the overflow.
Affected products
-
- Version 0StatusaffectedConstraints<0.088_001
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to CryptX 0.088_001 or later.
Red Hat statement
This IMPORTANT stack buffer overflow in perl-CryptX affects four AEAD decrypt_verify helpers. Exploitation requires no authentication and can be network-accessible if applications process untrusted cryptographic input. Impact is high to confidentiality, integrity, and availability through potential arbitrary code execution. Fixed in versions 0.088 (gcm) and 0.088_001 (ccm, chacha20poly1305, eax).
References (8)
- http://www.openwall.com/lists/oss-security/2026/05/28/10
- https://access.redhat.com/security/cve/CVE-2026-41565 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2482740 Issue Tracking
- https://github.com/DCIT/perl-CryptX/commit/57e69e541b0718ca8724c2f61514322a2d859bc1.patch patch
- https://github.com/DCIT/perl-CryptX/commit/7e56347d420aaf43b2ee1586f4a230492ccf1642.patch patch
- https://metacpan.org/release/MIK/CryptX-0.088_001 release-notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-41565
- https://www.cve.org/CVERecord?id=CVE-2026-41565
Change history (0)
No recorded changes yet.