CVE-2026-12087: Socket versions before 2.041 for Perl have an out-of-bounds heap read
Published Jun 15, 2026
·Updated
Socket versions before 2.041 for Perl have an out-of-bounds heap read
Affected Software
5 affected componentsFixes available
cpan/Socket<2.041
Microsoft azl3 perl 5.38.2-509<5.38.2-511
5.38.2-511
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.38.2-511 - Upgrade
Upgrade
Perl Socketto a version that resolves this vulnerability.Fixed in 2.041
Event History
Jun 15, 2026
CVE Published
via MITRE·09:11 PM
Data Sourced
via MITRE·09:11 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Jun 19, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:01 AM
Affected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Aug 15, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-12087?
CVE-2026-12087 is rated with a risk score of 30, indicating a medium severity vulnerability.
2
How do I fix CVE-2026-12087?
To fix CVE-2026-12087, upgrade to socket version 2.041 or later.
3
What type of vulnerability is CVE-2026-12087?
CVE-2026-12087 is an out-of-bounds heap read vulnerability in the Socket module for Perl.
4
Which versions of the Socket module are affected by CVE-2026-12087?
CVE-2026-12087 affects Socket versions prior to 2.041.
5
What consequences can CVE-2026-12087 cause?
CVE-2026-12087 may lead to untrusted memory access, potentially enabling exploitation of the affected application.