Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41565

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 9.8

Описание

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the buffer. Version 0.088 added the clamp to gcm_decrypt_verify, and 0.088_001 added it to the other three. Any caller of an affected helper that forwards an attacker-controlled tag longer than the buffer can trigger the overflow.

A flaw was found in perl-CryptX. A stack buffer overflow vulnerability exists in the AEAD (Authenticated Encryption with Associated Data) decrypt_verify helper routines. An attacker who can control the length of the authentication tag provided to these routines can cause a buffer overflow, potentially leading to arbitrary code execution or a denial of service.

Отчет

This IMPORTANT stack buffer overflow in perl-CryptX affects four AEAD decrypt_verify helpers. Exploitation requires no authentication and can be network-accessible if applications process untrusted cryptographic input. Impact is high to confidentiality, integrity, and availability through potential arbitrary code execution. Fixed in versions 0.088 (gcm) and 0.088_001 (ccm, chacha20poly1305, eax).

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2482740perl-CryptX: perl-CryptX: Stack buffer overflow allows arbitrary code execution via a crafted authentication tag.

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the buffer. Version 0.088 added the clamp to gcm_decrypt_verify, and 0.088_001 added it to the other three. Any caller of an affected helper that forwards an attacker-controlled tag longer than the buffer can trigger the overflow.

CVSS3: 7.5
nvd
2 месяца назад

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the buffer. Version 0.088 added the clamp to gcm_decrypt_verify, and 0.088_001 added it to the other three. Any caller of an affected helper that forwards an attacker-controlled tag longer than the buffer can trigger the overflow.

CVSS3: 7.5
debian
2 месяца назад

CryptX versions before 0.088_001 for Perl have a stack buffer overflow ...

CVSS3: 7.5
github
2 месяца назад

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the buffer. Version 0.088 added the clamp to gcm_decrypt_verify, and 0.088_001 added it to the other three. Any caller of an affected helper that forwards an attacker-controlled tag longer than the buffer can trigger the overflow.

suse-cvrf
2 месяца назад

Security update for perl-CryptX

9.8 Critical

CVSS3