Executive brief
A vulnerability in the Data::Deque::Shared Perl module allows local users on a shared system to read sensitive data stored in memory-mapped files. Because the module creates temporary files with insecure permissions, an attacker could also trick the software into writing data to unauthorized locations or intercepting communications between different parts of an application. This could lead to the exposure of private information or disruption of services on multi-user systems.
Technical details
The vulnerability exists in deque.h where the open() system call is used with O_RDWR|O_CREAT and a mode of 0666. Due to default umask settings (typically 022), this results in world-readable files (0644) in shared directories like /tmp or /dev/shm. Furthermore, the absence of O_EXCL and O_NOFOLLOW flags allows a local attacker to perform symlink attacks or win a race condition by pre-planting a file at the expected path. This enables unauthorized reading of IPC payloads or redirection of file operations. The issue is addressed in version 0.06.
Affected products
- EGOR (vividsnow) Data::Deque::Shared < 0.06
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory