Executive brief
A vulnerability in the Data::PubSub::Shared Perl module, which is used for high-performance communication between different processes on a computer, could allow local users to spy on or interfere with private data. Because the software creates temporary files with insecure permissions and fails to verify if those files have been tampered with, a malicious user on the same system could read sensitive message payloads or redirect the application to write data to unauthorized locations. This could lead to the exposure of internal application data or a disruption of service.
Technical details
Data::PubSub::Shared versions prior to 0.07 utilize insecure file operations when creating mmap backing files in shared directories like /tmp or /dev/shm. Specifically, the module uses open() with mode 0666, which results in world-readable files (0644) under standard umask settings, exposing Inter-Process Communication (IPC) payloads to all local users. Furthermore, the absence of O_EXCL and O_NOFOLLOW flags in the open() call allows a local attacker to win a race condition by pre-planting a file or a symbolic link at the expected path, potentially leading to unauthorized data access or arbitrary file writes. The issue was addressed in version 0.07 by changing the default file mode to 0600 and hardening the file opening logic.
Affected products
- EGOR (vividsnow) Data::PubSub::Shared before 0.07
Timeline
- 2026-07-03: patched: Version 0.07 released with security hardening.
- 2026-07-21: disclosed: CVE-2026-64617 published.