{"id":"CVE-2026-8376","title":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c…","summary":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-680"],"vendor":"perl","product":"perl","affected":["perl <= 5.43.10"],"published":"2026-05-26","updated":"2026-09-08","sourceUpdated":"2026-09-08T22:19:18.373","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","references":[{"url":"https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/05/26/1","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org","score-dispute"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-05-27T18:03:45.554441Z"},"scores":{"nvd":9.8,"adp":7.3},"epss":0.00443,"epssPercentile":0.37801,"ingestedAt":"2026-09-08T22:12:31.038Z","slug":"CVE-2026-8376","body":"## Overview\n\nPerl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.\n\n## Affected\n\n- `perl <= 5.43.10`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":7197,"id":"CVE-2026-8376","ts":1788909268383,"field":"cvss","old":"7.3","new":"9.8"},{"seq":7196,"id":"CVE-2026-8376","ts":1788909268383,"field":"severity","old":"high","new":"critical"}]}