THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-8376 (CRITICAL 9.8) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring b

[NVD] CVE-2026-8376 (CRITICAL 9.8) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring b

lownvdPublished 2026-05-26

CVE-2026-8376 CVSS: 9.8 CRITICAL Published: 2026-05-26T00:16:57.150

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.

Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quanti

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-8376