CVE-2026-12087: Socket versions before 2.041 for Perl have an out-of-bounds heap read
Last updated 27 August 2026
Other sources
Socket versions before 2.041 for Perl have an out-of-bounds heap read
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.38.2-511 - Upgrade
Upgrade
debian/libsocket-perlto a version that resolves this vulnerability.Fixed in 2.041-1 - Upgrade
Upgrade
debian/perlto a version that resolves this vulnerability.Fixed in 5.42.3-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.041
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12087?
CVE-2026-12087 is rated with a risk score of 30, indicating a medium severity vulnerability.
How do I fix CVE-2026-12087?
To fix CVE-2026-12087, upgrade to socket version 2.041 or later.
What type of vulnerability is CVE-2026-12087?
CVE-2026-12087 is an out-of-bounds heap read vulnerability in the Socket module for Perl.
Which versions of the Socket module are affected by CVE-2026-12087?
CVE-2026-12087 affects Socket versions prior to 2.041.
What consequences can CVE-2026-12087 cause?
CVE-2026-12087 may lead to untrusted memory access, potentially enabling exploitation of the affected application.