CVE-2026-59146: Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot
Robert Rothenberg 21 Jul 2026 19:26 UTC
========================================================================
CVE-2026-59146 CPAN Security Group
========================================================================
CVE ID: CVE-2026-59146
Distribution: Data-SpatialHash-Shared
Versions: before 0.02
MetaCPAN: https://metacpan.org/dist/Data-SpatialHash-Shared
VCS Repo: https://github.com/vividsnow/perl5-data-spatialhash-shared
Data::SpatialHash::Shared versions before 0.02 for Perl allow
out-of-bounds reads and writes via unvalidated bucket, link and
free-list indices in sph_walk_cell and sph_alloc_slot
Description
-----------
Data::SpatialHash::Shared versions before 0.02 for Perl allow
out-of-bounds reads and writes via unvalidated bucket, link and
free-list indices in sph_walk_cell and sph_alloc_slot.
The attach-time validator sph_validate_header checks the header scalars
and region layout against the file size, but does not validate the
array contents it then trusts. sph_walk_cell reads entries[buckets[b]]
and follows each entry's next link raw, and sph_alloc_slot writes
through a file-stored free_head index, none bounded against the entry
count (max_entries).
A local peer that can write the backing file can leave the header valid
while poisoning the bucket chain and free list, so a query reads
through an out-of-bounds bucket and next index and an insert writes
through an out-of-bounds free-list head, corrupting memory or crashing
the process.
Problem types
-------------
- CWE-787 Out-of-bounds Write
- CWE-125 Out-of-bounds Read
Workarounds
-----------
For deployments that cannot upgrade to 0.02, place the backing file in
a directory writable only by the owning user, so a local peer cannot
tamper with the bucket chain and free list.
Solutions
---------
Upgrade to Data::SpatialHash::Shared 0.02 or later, which bounds every
entry index against the entry count before dereferencing it.
References
----------
https://metacpan.org/release/EGOR/Data-SpatialHash-Shared-0.02/diff/EGOR/Data-SpatialHash-Shared-0.01#sphash.h
https://metacpan.org/release/EGOR/Data-SpatialHash-Shared-0.02/changes