Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-85644— XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference

Quick assessment

Affected
CVE-2026-85644
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Perl 模块 版本 0.40 至 0.49 中存在一个漏洞:它将数字误判为数组引用(array reference)。 为列表关联中缀操作符生成的包装函数会检查其参数是否为数组引用,但它在测试时使用的是 而非 。 读取的是一个仅在 为真时才持有被引用对象地址的联合(union)槽位,因此该检查实际上并未验证该值确实是一个引用。对于整数(IV)或浮点数(NV),该槽位存储的是数值本身;此时 会返回调用者提供的数值,而 会尝试从偏移量 12 处解引用该值。这通常会导致分段错误(segmentation fault)。

AI Predicted 8.1 Difficulty: Easy

Affected Version Matrix 1

VendorProduct Version RangeStatus
None None 0.40≤ 0.49 affected

I. Basic Information for CVE-2026-85644

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference
Source: CVE Program / CVE List V5
Vulnerability Description
XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references, but it tests using SvRV() rather than SvROK(). SvRV() reads a union slot that only holds a referent once SvROK(sv) is true, so the guard never validates that it is a reference. For an IV or NV that slot holds the number itself, SvRV() returns the caller's value and SvTYPE() dereferences it at offset 12. This will generally result in a segmentation fault. An application that hands the wrapper a list built from decoded input (for example, from JSON) lets whoever supplies a number in that list choose the address that the interpreter dereferences. An ordinary string's byte 12 is rarely SVt_PVAV so the guard croaks by luck, but an attacker-crafted string carrying 0x0b there passes, and the buffer is then used as an AV head, with AvARRAY taken from bytes 16-23 and its entries pushed onto the Perl stack as live SVs. A simple proof-of-concept uses the zip operator: use Syntax::Operator::Zip 'zip'; my @args = ([1], 2); zip(@args);
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0.40 ~ 0.49 -

II. Public POCs for CVE-2026-85644

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85644

请登录查看更多情报信息。

Other References for CVE-2026-85644 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85644

No comments yet


Leave a comment