Junglewise Threat Intelligence

CVE-2026-8376: Perl heap buffer overflow in regular expression compilation

CVE-2026-8376 · Severity: info · Published 2026-05-26

Vendors: Perl Foundation.

Executive brief

Perl is a widely used programming language for web development, system administration, and network programming. A vulnerability in its regular expression engine allows an attacker to cause a memory crash or potentially execute unauthorized code by providing a specially crafted search pattern. This issue specifically affects 32-bit systems and occurs when the application processes untrusted input as a regular expression.

Technical details

A heap buffer overflow exists in Perl's regular expression compiler (regcomp_study.c) within the Perl_study_chunk function. The vulnerability is caused by an integer overflow (CWE-680) where the compiler calculates the size of a joined substring buffer in characters rather than bytes. On 32-bit systems, a quantified fixed substring with a large minimum count can cause the byte length calculation (mincount * l) to overflow the SSize_t type. This results in an undersized memory allocation via SvGROW, leading to a buffer overflow when the string is subsequently copied. An attacker who can provide a malicious regular expression to be compiled can trigger this overflow at compile time. A patch is available in the upstream repository.

Affected products

  • Perl Foundation Perl through 5.43.10

Timeline

  • 2026-04-24: disclosed: Issue reported to Perl maintainers
  • 2026-05-20: patched: Fix merged to Perl development branch (blead)
  • 2026-05-26: advisory: Public disclosure of CVE-2026-8376

References