Executive brief
Data::SortedSet::Shared is a Perl library used to manage sorted data sets in shared memory. A vulnerability in how the library handles shared data files allows a local user with write access to those files to corrupt the internal data structure. This can cause applications using the library to crash or potentially leak sensitive information from the computer's memory.
Technical details
An out-of-bounds (OOB) read vulnerability exists in Data::SortedSet::Shared due to insufficient validation of node indices within mmap'd segments. While the attach-time validator 'ss_validate_header' checks the root index, it fails to bound child, leftmost, or rightmost node indices against the 'node_capacity'. A local attacker with write access to the backing file can poison these tree links. Subsequent rank, min, or max queries will then dereference these unvalidated indices, leading to an OOB read that can result in a process crash or disclosure of adjacent memory. The issue is addressed in version 0.03.
Affected products
- EGOR (vividsnow) Data::SortedSet::Shared < 0.03
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory