Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9265— Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path

AI Predicted 6.5 Difficulty: Moderate EPSS 0.63% · P47

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 1

VendorProductVersion RangeStatus
JONASBNCrypt::OpenSSL::PKCS12< 1.96affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9265

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path
Source: CVE Program / CVE List V5
Vulnerability Description
Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator. Downstream callers run strlen() on the result and pass the inflated length to newSVpvn(), copying attacker-influenced adjacent heap bytes into a Perl scalar.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
JONASBN Crypt::OpenSSL::PKCS12 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
JONASBN Crypt::OpenSSL::PKCS12是JONASBN的Perl加密模块。 JONASBN Crypt::OpenSSL::PKCS12 1.96之前版本存在缓冲区错误漏洞,该漏洞源于print_attribute UTF8STRING路径存在堆越界读取,print_attribute()函数通过strncpy将UTF8STRING ASN.1属性值复制到按声明长度精确分配的堆缓冲区,未添加NUL终止符,下游调用者对结果执行strlen()并将膨胀后的长度传递给newSVpvn(),
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
JONASBNCrypt::OpenSSL::PKCS12 0 ~ 1.96 -

II. Public POCs for CVE-2026-9265

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9265

登录查看更多情报信息。

Patches & Fixes for CVE-2026-9265 (1)

Vendor Advisories for CVE-2026-9265 (1)

Vendor Pages for CVE-2026-9265 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9265

No comments yet


Leave a comment