Back

CRITICAL

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers

Published May 28, 2026

Description

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers.

The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the buffer. Version 0.088 added the clamp to gcm_decrypt_verify, and 0.088_001 added it to the other three.

Any caller of an affected helper that forwards an attacker-controlled tag longer than the buffer can trigger the overflow.

Affected products

Remediation

Vendor solution

Upgrade to CryptX 0.088_001 or later.

Red Hat statement

This IMPORTANT stack buffer overflow in perl-CryptX affects four AEAD decrypt_verify helpers. Exploitation requires no authentication and can be network-accessible if applications process untrusted cryptographic input. Impact is high to confidentiality, integrity, and availability through potential arbitrary code execution. Fixed in versions 0.088 (gcm) and 0.088_001 (ccm, chacha20poly1305, eax).

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published May 28, 2026
Updated May 29, 2026
Reserved Apr 21, 2026
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 28, 2026