Junglewise Threat Intelligence

CVE-2026-8507: Perl Crypt::OpenSSL::PKCS12 heap overflow in print_attribute

CVE-2026-8507 · Severity: info · CVSS 9.8 · Published 2026-05-17

Technologies: Perl CPAN Crypt::OpenSSL::PKCS12. Vendors: Perl CPAN.

Executive brief

A vulnerability in the Crypt::OpenSSL::PKCS12 Perl library could allow an attacker to execute malicious code or crash a system. This library is used to process PKCS#12 files, which typically contain digital certificates and private keys. By providing a specially crafted certificate file, an attacker could exploit a memory handling error to gain unauthorized access or disrupt operations.

Technical details

An integer overflow vulnerability exists in the print_attribute function within PKCS12.xs. When processing an OCTET STRING or BIT STRING attribute on a SAFEBAG, the library multiplies the attribute length by 4 to allocate a buffer. If the length is >= 1 GiB (0x40000000), the 32-bit integer multiplication overflows to 0, resulting in a near-zero byte allocation via Renew(). Subsequent data copying via get_hex() then writes approximately 3 GiB of data out-of-bounds on the heap. This can be triggered remotely if an application uses info() or info_as_hash() on untrusted PKCS12 files. The issue is fixed in version 1.95 by adding explicit length guards and promoting the calculation to size_t.

Affected products

  • Perl CPAN Crypt::OpenSSL::PKCS12 through 1.94

Timeline

  • 2026-05-17: disclosed
  • 2026-05-17: patched: Fixed in version 1.95
  • 2026-05-17: advisory

References