CVE-2026-57433

ubuntu perl: Ganzzahlueberlauf

criticalEPSS 0.4%

Affected

  • ubuntu/perl 5.26.1-6ubuntu0.7+esm3..*
  • ubuntu/perl 5.30.0-9ubuntu0.5+esm3..*
  • ubuntu/perl 5.34.0-3ubuntu1.8..*
  • ubuntu/perl 5.18.2-2ubuntu1.7+esm8..*
  • ubuntu/perl 5.22.1-9ubuntu0.9+esm3..*

Description

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

Affected operating systems

  • linux

    ubuntu / perlbionic

  • linux

    ubuntu / perlfocal

  • linux

    ubuntu / perljammy

  • linux

    ubuntu / perltrusty

  • linux

    ubuntu / perlxenial

Metrics

9.8
Source: nvd-v3
27.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
critical
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-13 17:17 UTC
CWE-190

Weakness classes (CWE)

  • CWE-190Base

    Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

    cwe.mitre.org →

References & sources

Linked advisories