CVE-2026-59143: Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked Robert Rothenberg 21 Jul 2026 19:28 UTC

========================================================================
CVE-2026-59143                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-59143
   Distribution:  Data-RoaringBitmap-Shared
       Versions:  before 0.02

       MetaCPAN: https://metacpan.org/dist/Data-RoaringBitmap-Shared
       VCS Repo:
https://github.com/vividsnow/perl5-data-roaringbitmap-shared

Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an
out-of-bounds read via an unvalidated container offset and cardinality
in rb_contains_locked

Description
-----------
Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an
out-of-bounds read via an unvalidated container offset and cardinality
in rb_contains_locked.

The attach-time validator rb_validate_header checks the header scalars
and region layout against the file size, but does not validate the
bucket contents it then trusts. rb_contains_locked forms a container
pointer as pool + container_off * 8192 from a raw file-stored offset
and then searches over a file-stored cardinality, neither bounded
against the container pool capacity or the fixed 8192-byte slot size.

A local peer that can write the backing file can leave the header valid
while poisoning a bucket, so the next membership query dereferences a
file-controlled wild pointer and scans a file-controlled count, reading
adjacent memory or crashing the process.

Problem types
-------------
- CWE-125 Out-of-bounds Read

Workarounds
-----------
For deployments that cannot upgrade to 0.02, place the backing file in
a directory writable only by the owning user, so a local peer cannot
tamper with the buckets the query path reads.

Solutions
---------
Upgrade to Data::RoaringBitmap::Shared 0.02 or later, which clamps an
out-of-range container offset to the empty sentinel and caps the
cardinality at the slot capacity.

References
----------
https://metacpan.org/release/EGOR/Data-RoaringBitmap-Shared-0.02/diff/EGOR/Data-RoaringBitmap-Shared-0.01#roaring.h
https://metacpan.org/release/EGOR/Data-RoaringBitmap-Shared-0.02/changes