Junglewise Threat Intelligence

CVE-2026-12844: DROLSKY List::SomeUtils::XS heap buffer overflow in pairwise function

CVE-2026-12844 · Severity: info · CVSS 0 · Published 2026-06-25

Executive brief

List::SomeUtils::XS is a Perl library used to provide high-performance utility functions for processing lists and arrays. A security flaw in its 'pairwise' function could allow a specially crafted input to crash the application or potentially allow unauthorized code execution. This occurs when the library fails to properly allocate memory for very large sets of data, leading to memory corruption.

Technical details

A heap-based buffer overflow exists in List::SomeUtils::XS before version 0.59 within the pairwise() function. The vulnerability is caused by a logic error in how the internal buffer grows; the code uses a single bitwise shift (alloc <<= 2) to quadruple the buffer size once, rather than using a loop to ensure the buffer is large enough for the returned data. If a block call returns more than four times the current allocation in a single invocation, the subsequent copy operation writes past the end of the buffer. This results in heap corruption, which can lead to a denial of service or potentially arbitrary code execution. The issue is fixed in version 0.59 by implementing a while loop to ensure sufficient allocation.

Affected products

  • DROLSKY List::SomeUtils::XS < 0.59

Timeline

  • 2026-06-22: patched: Fix committed to GitHub repository
  • 2026-06-25: disclosed: CVE published to NVD

References