Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57433: Perl Storable versions before 3.41 can crash due to crafted data
CVE-2026-57433
Summary
Versions of Perl's Storable module before 3.41 can crash if it's given a specially crafted file. This can happen when the module tries to deserialize data that's been tampered with. To fix this, update to version 3.41 or later of the Storable module.
Original title
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.
retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and ...
Original description
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.
retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.
A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.
retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.
A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.
Vulnerability type
CWE-190
Integer Overflow
Published: 13 Jul 2026 · Updated: 20 Jul 2026 · First seen: 13 Jul 2026