CVE-2026-9265
描述
Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator. Downstream callers run strlen() on the result and pass the inflated length to newSVpvn(), copying attacker-influenced adjacent heap bytes into a Perl scalar.
如何修補 CVE-2026-9265
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
CVE-2026-9265 正在被利用嗎?
目前沒有被利用訊號。CVE-2026-9265 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- from 0