GHSA-5g35-5jrj-f39p · Severity: high — Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of...
Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.
Conclusion & alert: CVE-2026-57432 is rated Low Risk (37.4/100): CVSS High severity, with low exploitation likelihood (EPSS 0.21%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-07-14 | — | 0.21% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.4 | 3.1 | HIGH |
|
2.5 | 5.9 | [email protected] |
| 8.4 | 3.1 | HIGH |
|
2.5 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-5g35-5jrj-f39p · Severity: high — Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-57432 not yet assigned priority: Debian including 1 source packages (perl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 3, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-57432 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2026-57432/ |
ubuntu
|
medium | CVE-2026-57432 medium priority: Ubuntu including 1 source packages (perl), 8 status rows across 8 suites (bionic, focal, jammy, noble, resolute, trusty, upstream, xenial): needs-triage 8. | https://ubuntu.com/security/CVE-2026-57432 |
| URL | Tags |
|---|---|
| https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch | Patch |
| https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch | Patch |
| http://www.openwall.com/lists/oss-security/2026/07/13/6 | Mailing List Patch Third Party Advisory |