- Package:
- src:libxs-parse-keyword-perl
- Source:
- src:libxs-parse-keyword-perl
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-29 16:09:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for libxs-parse-keyword-perl. CVE-2026-85644[0]: | XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a | number as an array reference. The wrapper function XS::Parse::Infix | generates for a list-associative infix operator checks whether | arguments are array references, but it tests using SvRV() rather | than SvROK(). SvRV() reads a union slot that only holds a referent | once SvROK(sv) is true, so the guard never validates that it is a | reference. For an IV or NV that slot holds the number itself, SvRV() | returns the caller's value and SvTYPE() dereferences it at offset | 12. This will generally result in a segmentation fault. An | application that hands the wrapper a list built from decoded input | (for example, from JSON) lets whoever supplies a number in that list | choose the address that the interpreter dereferences. An ordinary | string's byte 12 is rarely SVt_PVAV so the guard croaks by luck, but | an attacker-crafted string carrying 0x0b there passes, and the | buffer is then used as an AV head, with AvARRAY taken from bytes | 16-23 and its entries pushed onto the Perl stack as live SVs. A | simple proof-of-concept uses the zip operator: use | Syntax::Operator::Zip 'zip'; my @args = ([1], 2); | zip(@args); If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-85644 https://www.cve.org/CVERecord?id=CVE-2026-85644 [1] https://lists.security.metacpan.org/cve-announce/msg/43916020/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libxs-parse-keyword-perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149243@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libxs-parse-keyword-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 29 Sep 2026 17:41:00 +0200
Source: libxs-parse-keyword-perl
Architecture: source
Version: 0.51-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1149243
Changes:
libxs-parse-keyword-perl (0.51-1) unstable; urgency=medium
.
* Import upstream version 0.51.
From 0.50:
- Use `SvROK` not `SvRV` to check for values being references
(CVE-2026-85644)
Closes: #1149243
* Update years of upstream and packaging copyright.
* Declare compliance with Debian Policy 4.7.4.
* Convert debian/watch to version 5.
Checksums-Sha1:
27e038ca116da77a400032014ab995d26d3df2ba 2600 libxs-parse-keyword-perl_0.51-1.dsc
3016e95c16a9c1d0ab79cc4b6652f3a4599d9d29 95209 libxs-parse-keyword-perl_0.51.orig.tar.gz
6a6dc562d715228789fc6cc40e29eb08ef12d720 3120 libxs-parse-keyword-perl_0.51-1.debian.tar.xz
768b3ba163e99e50f1487100ef0b29d568897ec3 171092 libxs-parse-keyword-perl_0.51-1.git.tar.xz
ed34dd953e75174272dd74d93c0a34e1cc02f4e6 17788 libxs-parse-keyword-perl_0.51-1_source.buildinfo
Checksums-Sha256:
be45c0b922365f20fd38fdb184964a5f00783a0aff21590c887907eed7c5c087 2600 libxs-parse-keyword-perl_0.51-1.dsc
9dcfdf4ca357caa6557c04bf6e215c1ef4784d5711ab246c5400b49863a3f61b 95209 libxs-parse-keyword-perl_0.51.orig.tar.gz
7ad8aa8332442ecf4c043fb13122382fae1effea07c2e5952c2f9e77e247b849 3120 libxs-parse-keyword-perl_0.51-1.debian.tar.xz
38c45c7cf02590dad2775920e1f682846ec04b788e409417437a9b9834be1939 171092 libxs-parse-keyword-perl_0.51-1.git.tar.xz
a1342a9b36c9071e584ac645c9c7710ab078bf361f7945eeb99041efdd137153 17788 libxs-parse-keyword-perl_0.51-1_source.buildinfo
Files:
8a5f34b9e94696afd3b3b814da75c09b 2600 perl optional libxs-parse-keyword-perl_0.51-1.dsc
55dcd9a3ac78ed62f5a2bbab98295696 95209 perl optional libxs-parse-keyword-perl_0.51.orig.tar.gz
c8aa11d59b2d736186a8afd1f6b2f375 3120 perl optional libxs-parse-keyword-perl_0.51-1.debian.tar.xz
a417414f8bcc6299cfb604072f22d3ab 171092 perl None libxs-parse-keyword-perl_0.51-1.git.tar.xz
6eca605ae99c3c9801f1f9f5910e0196 17788 perl optional libxs-parse-keyword-perl_0.51-1_source.buildinfo
Git-Tag-Info: tag=e5136807a6f9f685f520b453c821f52fbb39d63b fp=d1e1316e93a760a8104d85fabb3a68018649aa06
Git-Tag-Tagger: gregor herrmann <gregoa@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmq73OoACgkQYG0ITkaD
wHmw0RAAktzX5U1H+G+oFor8HNgdFBkAaJTxItdcjJviLVFx8eCUHPuAtBVK44Zr
52M7vAzkRClwHzGW5LJBjrNQKq5vNmZuTN0diPfKDbMQUg6VfTbSEnux/0405r5i
Ucl7ZY9CojwV6Q2knTCiGj54jxHR/IRLF/MtsDk3uud9TDDh0qN2J4A/QIg+5Jfy
/4TfhcZdL/ZuM1eHmTa8bstkh0Tu1JFrYkaJflHtqlc7Ujc60oLb86fTM1aHko5n
SDQhRmBGcA/hdOl8HifbTWr2yt06KxAe1HnyzUakVg45JN8oTYfRJN7x/JdvcCQY
ljBds9iupmU1Es8C3C2nwd/zvFEq7ZSE32nQg++zXhNlRzd6F+OtB/ddyN5pGkf8
FP13HW7+HSAQpIeFbJgSJ+8JA42bz3QPAGX7GfXQG4Lm4LuLD95C8AAR8kYprUdr
brlGEveg8HVz/xeYQmkuG9QwtX3kArEMVukaaCBhqmkHkU8MhBK5FOKFZeZ/VH4R
peE07GX9YfZVsQ3XipQeYQEVrV+LaB/dTgqtmoO3c9jfawutySD0FL+gG5fW2Gob
ImWykFVIfrPoZCNNc0o48e5SGxBGntVZzIAkSs9Jymj5hT4u9BWNXs/2DthWiMHq
v99NTi5LlQtFvC0+CzVrptgXtwMRF6F5JDCLfk1xjGJVZJD+BOQ=
=4KEi
-----END PGP SIGNATURE-----