Executive brief
Data::Buffer::Shared is a Perl module used to manage shared memory buffers between different processes. A security flaw in versions before 0.05 allows local users on the same system to read sensitive data stored in these buffers or trick the application into accessing unintended files. This could lead to the exposure of private information or unauthorized modification of system files if the application is running with elevated privileges.
Technical details
The vulnerability exists in buf_generic.h where mmap backing files are created using open() with mode 0666. Due to default umask settings (typically 022), this results in world-readable files (0644) in shared directories like /tmp or /dev/shm, allowing any local user to read IPC payloads. Additionally, the absence of the O_NOFOLLOW flag during the open call allows an attacker to plant a symlink at the expected path, potentially causing the application to read from or write to an arbitrary file. The issue is addressed in version 0.05 by changing the default creation mode to 0600 and hardening file handling.
Affected products
- EGOR (vividsnow) Data::Buffer::Shared before 0.05
Timeline
- 2026-07-03: patched: Version 0.05 released with security hardening.
- 2026-07-21: disclosed: CVE-2026-64613 published.