CVE-2026-107373: ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument Robert Rothenberg 10 Oct 2026 12:46 UTC

========================================================================
CVE-2026-107373                                      CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-107373

   Distribution:  ExtUtils-Typemaps-Default
       Versions:  before 1.06
       MetaCPAN: https://metacpan.org/dist/ExtUtils-Typemaps-Default
       VCS Repo:  https://github.com/tsee/extutils-typemap-default

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl
T_STD_STRING typemap may read the SV length before stringifying the
argument

Description
-----------
ExtUtils::Typemaps::STL::String versions before 1.06 for Perl
T_STD_STRING typemap may read the SV length before stringifying the
argument.

The typemap uses

     $var = std::string( SvPV_nolen($arg), SvCUR($arg) )

However, evaluation order for C++ arguments is not specified, and some
compilers may produce code that evalutes SvCUR($arg) first.

When $arg is not a string (for example, an interger, number or a
reference) then SvCUR will return an invalid value, and the program may
abort or segfault.

Problem types
-------------
- CWE-125 Out-of-bounds Read

Workarounds
-----------
For deployments that cannot be upgraded, ensure that arguments passed
to modules that use ExtUtils::Typemaps::Default are strngified.

Solutions
---------
Upgrade to ExtUtils::Typemaps::Default version 1.06 or later.

Rebuild any modules that use ExtUtils::Typemaps::Default as part of
their build process.

References
----------
https://metacpan.org/release/SMUELLER/ExtUtils-Typemaps-Default-1.06/changes
https://github.com/tsee/extutils-typemap-default/commit/a6b9c298b34ddadc582961403e715d292f82a22d
https://rt.cpan.org/Public/Bug/Display.html?id=94110
https://www.cve.org/CVERecord?id=CVE-2026-80490

Timeline
--------
- 2014-03-22: Issue reported in bugtracker for
   ExtUtils::Typemaps::Default version 1.05.
- 2014-06-10: Fix committed to the repository. Bugtracker issue closed.
- 2026-09-30: Issue reported to CPANSec.
- 2026-10-08: ExtUtils::Typemaps::Default version 1.06 released with a
   fix.