CVE-2018-18314: Buffer Overflow
Published Nov 5, 2018
·Updated
A flaw was found in Perl versions 5.18 through 5.28. A Heap-based buffer overflow
Upstream Patch: https://github.com/Perl/perl5/commit/19a498a461d7c81ae3507c450953d1148efecf4f
Other sources
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
— Launchpad
Affected Software
18 affected componentsFixes available
redhat/perl<5.26.3
5.26.3
redhat/perl<5.28.1
5.28.1
Perl Perl<5.26.3
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Debian Debian Linux=9.0
NetApp E-Series SANtricity OS Controller>=11.0<=11.40
NetApp Snap Creator Framework
NetApp Snapcenter
NetApp Snapdrive Unix
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=7.4
redhat Enterprise Linux=7.5
redhat Enterprise Linux=7.6
debian/perl
5.32.1-4+deb11u35.32.1-4+deb11u45.36.0-7+deb12u35.36.0-7+deb12u25.40.1-65.40.1-7
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 7, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 22, 2026
Data Sourced
via Ubuntu·06:09 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:10 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:10 PM
Description
Frequently Asked Questions
1
What is CVE-2018-18314?
CVE-2018-18314 is a vulnerability in Perl before version 5.26.3 that allows for a buffer overflow through a crafted regular expression.
2
How severe is CVE-2018-18314?
CVE-2018-18314 has a severity rating of 9.8 (Critical).
3
Which software versions are affected by CVE-2018-18314?
Perl versions up to and excluding 5.26.3 are affected.
4
How can I fix CVE-2018-18314?
To fix CVE-2018-18314, update Perl to version 5.26.3 or later.
5
Where can I find more information about CVE-2018-18314?
You can find more information about CVE-2018-18314 at the following references: [1] [2] [3].