Junglewise Threat Intelligence

CVE-2026-65066: Data::RingBuffer::Shared insecure file permissions and symlink following

CVE-2026-65066 · Severity: info · CVSS 5.1 · Published 2026-07-21

Vendors: EGOR.

Executive brief

Data::RingBuffer::Shared is a Perl library used for high-speed data sharing between different processes on a computer. A security flaw in versions before 0.04 allows any local user on the system to read sensitive data stored in these shared buffers. Additionally, a malicious user could trick the library into writing data to the wrong location or hijacking the communication channel, potentially leading to data theft or system instability.

Technical details

Data::RingBuffer::Shared versions prior to 0.04 contain multiple filesystem-related vulnerabilities in the creation of mmap backing files within ring.h. The library uses open() with mode 0666, which results in world-readable files (typically mode 0644) under standard umask settings, exposing IPC payloads to all local users. Furthermore, the call lacks O_EXCL and O_NOFOLLOW flags. Because these files are typically stored in shared directories like /tmp or /dev/shm, a local attacker can perform a symlink attack to redirect file operations or win a race condition by pre-planting a file to intercept or manipulate shared memory segments. The issue is resolved in version 0.04 by using mode 0600 and improved file opening logic.

Affected products

  • EGOR Data::RingBuffer::Shared < 0.04

Timeline

  • 2026-07-03: patched: Version 0.04 released with security hardening.
  • 2026-07-21: disclosed: CVE-2026-65066 published.

References