Bug 2542563 (CVE-2026-85644) - CVE-2026-85644 perl-XS-Parse-Keyword: perl-XS-Parse-Keyword: Denial of Service via improper array reference validation
Summary: CVE-2026-85644 perl-XS-Parse-Keyword: perl-XS-Parse-Keyword: Denial of Servic...
Keywords:
Status: NEW
Alias: CVE-2026-85644
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-28 16:32 UTC by OSIDB Bzimport
Modified: 2026-09-28 16:41 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-28 16:32:21 UTC
XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference.

The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references, but it tests using SvRV() rather than SvROK(). SvRV() reads a union slot that only holds a referent once SvROK(sv) is true, so the guard never validates that it is a reference. For an IV or NV that slot holds the number itself, SvRV() returns the caller's value and SvTYPE() dereferences it at offset 12. This will generally result in a segmentation fault.

An application that hands the wrapper a list built from decoded input (for example, from JSON) lets whoever supplies a number in that list choose the address that the interpreter dereferences.

An ordinary string's byte 12 is rarely SVt_PVAV so the guard croaks by luck, but an attacker-crafted string carrying 0x0b there passes, and the buffer is then used as an AV head, with AvARRAY taken from bytes 16-23 and its entries pushed onto the Perl stack as live SVs.

A simple proof-of-concept uses the zip operator:

    use Syntax::Operator::Zip 'zip';

    my @args = ([1], 2);
    zip(@args);


Note You need to log in before you can comment on or make changes to this bug.