目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-59142— EGOR Data::HashMap::Shared 缓冲区错误漏洞

AI 预测 5.5 利用难度: 较易 EPSS 0.34% · P26

影响版本矩阵 1

厂商产品版本范围状态
EGORData::HashMap::Shared< 0.14affected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-59142 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy
来源: CVE Program / CVE List V5
Vulnerability Description
Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. shm_str_copy does memcpy(dst, arena + off, len) with off and len read raw from the mmap'd segment and unbounded, on the each, keys, values, pop, shift, take, swap, drain and cursor paths. The get path bounds off and len separately and is not affected. A local peer that can write the backing file can leave the header valid while poisoning a record's offset and length, so iterating or draining the map copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
来源: CVE Program / CVE List V5
Vulnerability Title
EGOR Data::HashMap::Shared 缓冲区错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
EGOR Data::HashMap::Shared是EGOR个人开发者开源的一个 Perl 模块,用于多进程共享内存哈希映射,支持 LRU 淘汰和逐键 TTL。 EGOR Data::HashMap::Shared 0.14之前版本存在缓冲区错误漏洞,该漏洞源于未验证的偏移量和长度导致越界读取,通过shm_str_copy函数读取相邻内存或导致进程崩溃。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
EGORData::HashMap::Shared 0 ~ 0.14 -

二、漏洞 CVE-2026-59142 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-59142 的情报信息

登录查看更多情报信息。

CVE-2026-59142 补丁与修复 (1)

CVE-2026-59142 其他参考 (1)

同批安全公告 · EGOR · 2026-07-21 · 共 23 条

CVE-2026-59143EGOR Data::RoaringBitmap::Shared 缓冲区错误漏洞
CVE-2026-65068EGOR Data::SpatialHash::Shared 后置链接漏洞
CVE-2026-65062EGOR Data::SortedSet::Shared 后置链接漏洞
CVE-2026-65065EGOR Data::RoaringBitmap::Shared 后置链接漏洞
CVE-2026-65069EGOR Data::DisjointSet::Shared 后置链接漏洞
CVE-2026-65066EGOR Data::RingBuffer::Shared 后置链接漏洞
CVE-2026-65063EGOR Data::RadixTree::Shared 后置链接漏洞
CVE-2026-65067EGOR Data::Intern::Shared 后置链接漏洞
CVE-2026-65064EGOR Data::HashMap::Shared 后置链接漏洞
CVE-2026-65061EGOR Data::ReqRep::Shared 后置链接漏洞
CVE-2026-59147EGOR Data::DisjointSet::Shared 缓冲区错误漏洞
CVE-2026-59140EGOR Data::SortedSet::Shared 缓冲区错误漏洞
CVE-2026-59145EGOR Data::Intern::Shared 缓冲区错误漏洞
CVE-2026-59146EGOR Data::SpatialHash::Shared 缓冲区错误漏洞
CVE-2026-59144EGOR Data::RingBuffer::Shared 缓冲区错误漏洞
CVE-2026-64613EGOR Data::Buffer::Shared 后置链接漏洞
CVE-2026-64617EGOR Data::PubSub::Shared 后置链接漏洞
CVE-2026-64615EGOR Data::Graph::Shared 后置链接漏洞
CVE-2026-64614EGOR Data::Deque::Shared 后置链接漏洞
CVE-2026-64616EGOR Data::NDArray::Shared 后置链接漏洞

显示前 20 条,共 23 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-59142

暂无评论


发表评论