CVE-2026-59142: Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy Robert Rothenberg 21 Jul 2026 19:28 UTC

========================================================================
CVE-2026-59142                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-59142
   Distribution:  Data-HashMap-Shared
       Versions:  before 0.14

       MetaCPAN:  https://metacpan.org/dist/Data-HashMap-Shared
       VCS Repo: https://github.com/vividsnow/perl5-data-hashmap-shared

Data::HashMap::Shared versions before 0.14 for Perl allow an
out-of-bounds read via an unvalidated arena offset and length in
shm_str_copy

Description
-----------
Data::HashMap::Shared versions before 0.14 for Perl allow an
out-of-bounds read via an unvalidated arena offset and length in
shm_str_copy.

The attach-time validator shm_validate_header checks the header scalars
and region layout against the file size, but does not validate the
array contents it then trusts. shm_str_copy does memcpy(dst, arena +
off, len) with off and len read raw from the mmap'd segment and
unbounded, on the each, keys, values, pop, shift, take, swap, drain and
cursor paths. The get path bounds off and len separately and is not
affected.

A local peer that can write the backing file can leave the header valid
while poisoning a record's offset and length, so iterating or draining
the map copies a file-controlled offset and length out of the arena,
reading adjacent memory or crashing the process.

Problem types
-------------
- CWE-125 Out-of-bounds Read

Workarounds
-----------
For deployments that cannot upgrade to 0.14, place the backing file in
a directory writable only by the owning user, so a local peer cannot
tamper with the records the iteration paths read.

Solutions
---------
Upgrade to Data::HashMap::Shared 0.14 or later, which bounds the arena
offset and length in shm_str_copy before the copy.

References
----------
https://metacpan.org/release/EGOR/Data-HashMap-Shared-0.14/diff/EGOR/Data-HashMap-Shared-0.13#shm_generic.h
https://metacpan.org/release/EGOR/Data-HashMap-Shared-0.14/changes