CVE-2026-9265

Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator. Downstream callers run strlen() on the result and pass the inflated length to newSVpvn(), copying attacker-influenced adjacent heap bytes into a Perl scalar.
Configurations

No configuration.

History

22 Jun 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

20 Jun 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-20 02:16

Updated : 2026-06-22 18:45


NVD link : CVE-2026-9265

Mitre link : CVE-2026-9265

CVE.ORG link : CVE-2026-9265


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read