Junglewise Threat Intelligence

CVE-2026-41565: Perl CryptX stack buffer overflow in AEAD decrypt_verify helpers

CVE-2026-41565 · Severity: info · CVSS 7.5 · Published 2026-05-28

Vendors: Perl CPAN.

Executive brief

CryptX, a popular Perl library for cryptographic operations, contains a vulnerability in its data decryption and verification functions. An attacker can provide a specially crafted authentication tag that is larger than expected, causing the application to crash or potentially execute unauthorized code. This could lead to a denial of service or compromise the security of systems relying on this library for secure data handling.

Technical details

A stack-based buffer overflow exists in the XS routines for gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify, and eax_decrypt_verify in CryptX before version 0.088_001. The vulnerability is caused by copying a caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without validating the input length. An attacker who can control the tag length passed to these helpers can overwrite the stack memory. This can result in a denial of service (application crash) or potentially remote code execution depending on the environment and stack protections. The issue was partially addressed in 0.088 for GCM and fully resolved in 0.088_001 for the remaining algorithms by clamping the input length.

Affected products

  • Perl CPAN CryptX before 0.088_001

Timeline

  • 2026-05-28: advisory: CVE-2026-41565 published by NVD
  • 2026-04-22: patched: Initial fix for GCM helper in version 0.088
  • 2026-04-27: patched: Complete fix for remaining helpers in version 0.088_001

References