CVE-2026-107373 PUBLISHED

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument

Assigner: CPANSec
Reserved: 07.10.2026 Published: 10.10.2026 Updated: 10.10.2026

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.

The typemap uses

<pre>$var = std::string( SvPV_nolen($arg), SvCUR($arg) ) </pre>

However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first.

When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault.

Product Status

Package Collection https://cpan.org/modules
Package Name ExtUtils-Typemaps-Default
Versions Default: unaffected
  • affected from 0 to 1.06 (excl.)

Workarounds

For deployments that cannot be upgraded, ensure that arguments passed to modules that use ExtUtils::Typemaps::Default are strngified.

Solutions

Upgrade to ExtUtils::Typemaps::Default version 1.06 or later.

Rebuild any modules that use ExtUtils::Typemaps::Default as part of their build process.

References

Problem Types

  • CWE-125 Out-of-bounds Read CWE