Junglewise Threat Intelligence

CVE-2026-65068: EGOR Data::SpatialHash::Shared insecure file permissions and symlink following

CVE-2026-65068 · Severity: info · Published 2026-07-21

Vendors: EGOR.

Executive brief

Data::SpatialHash::Shared is a Perl module used for managing shared spatial data in memory. In versions before 0.02, the module creates temporary files with insecure permissions and fails to verify if the file path has been tampered with. This allows a local attacker on the same system to read sensitive data or trick the application into modifying files it shouldn't access, potentially leading to data theft or system instability.

Technical details

The vulnerability exists in sphash.h where the mmap backing file is created using open(path, O_RDWR|O_CREAT, 0666). Due to the lack of O_EXCL and O_NOFOLLOW flags, the application is susceptible to symlink attacks and race conditions where an attacker can pre-plant a file or link at the expected path (typically in /tmp or /dev/shm). Additionally, the use of mode 0666 results in world-readable files (0644 under default umask), allowing any local user to read IPC payloads. The issue is addressed in version 0.02 by using mode 0600 and implementing hardening measures.

Affected products

  • EGOR Data::SpatialHash::Shared < 0.02

Timeline

  • 2026-07-03: patched: Version 0.02 released with security hardening.
  • 2026-07-21: advisory: CVE-2026-65068 published.

References