logo

CVE-2026-57433: Perl Storable Signed Integer Overflow in SX_HOOK Deserialization

ID: d1b6533d-a8b3-537c-a8a8-5e347066a8f6

STIX ID: report--d1b6533d-a8b3-537c-a8a8-5e347066a8f6

Feed Name: CosmicBytez Labs

Threat Score
88/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

...
...

A critical signed integer overflow (CVE-2026-57433, CVSS 9.8) in Perl's Storable module (< 3.41) allows an attacker to supply a crafted SX_HOOK record with an I32_MAX item count, causing count+1 to wrap negative and invoking av_extend with a negative size, resulting in heap corruption and potential arbitrary code execution; remediation is to upgrade Storable to 3.41+ and avoid deserializing untrusted data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.