Executive brief
Perl is a widely used programming language for web development, system administration, and network programming. A vulnerability in its regular expression engine allows an attacker to cause a memory crash or potentially execute unauthorized code by providing a specially crafted search pattern. This issue specifically affects 32-bit systems and occurs when the application processes untrusted input as a regular expression.
Technical details
A heap buffer overflow exists in Perl's regular expression compiler (regcomp_study.c) within the Perl_study_chunk function. The vulnerability is caused by an integer overflow (CWE-680) where the compiler calculates the size of a joined substring buffer in characters rather than bytes. On 32-bit systems, a quantified fixed substring with a large minimum count can cause the byte length calculation (mincount * l) to overflow the SSize_t type. This results in an undersized memory allocation via SvGROW, leading to a buffer overflow when the string is subsequently copied. An attacker who can provide a malicious regular expression to be compiled can trigger this overflow at compile time. A patch is available in the upstream repository.
Affected products
- Perl Foundation Perl through 5.43.10
Timeline
- 2026-04-24: disclosed: Issue reported to Perl maintainers
- 2026-05-20: patched: Fix merged to Perl development branch (blead)
- 2026-05-26: advisory: Public disclosure of CVE-2026-8376