Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57433

Опубликовано: 13 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

A flaw was found in Storable. This vulnerability allows a remote attacker to cause a denial of service (DoS) by providing a specially crafted data blob during deserialization. The flaw occurs due to a signed integer overflow when processing an SX_HOOK record, leading to a negative count being passed to an internal function, which then causes the application to terminate unexpectedly.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesperl-StorableNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2499728Storable: Storable: Denial of Service via signed integer overflow in deserialization

EPSS

Процентиль: 29%
0.00357
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
2 месяца назад

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

CVSS3: 9.8
nvd
2 месяца назад

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

CVSS3: 9.8
msrc
около 2 месяцев назад

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record

CVSS3: 9.8
debian
2 месяца назад

Storable versions before 3.41 for Perl have a signed integer overflow ...

CVSS3: 9.8
github
2 месяца назад

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

EPSS

Процентиль: 29%
0.00357
Низкий

7.5 High

CVSS3