CVE-2026-8376: Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
Last updated 26 June 2026
Other sources
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perlstudychunk in regcompstudy.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount l could overflow SSizet, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.
A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.
— MITRE
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/perlto a version that resolves this vulnerability.Fixed in 5.40.1-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.38.2-511 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.38.2-512 - Upgrade
Upgrade
perlto a version that resolves this vulnerability.Fixed in 5.40.5-RC1 - Upgrade
Upgrade
perlto a version that resolves this vulnerability.Fixed in 5.42.3-RC1 - Upgrade
Upgrade
perlto a version that resolves this vulnerability.Fixed in 5.44.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8376?
The severity of CVE-2026-8376 is rated as risk level 28.
How do I fix CVE-2026-8376?
To fix CVE-2026-8376, upgrade to a future release of Perl or apply the upstream patch.
What versions of Perl are affected by CVE-2026-8376?
Perl versions through 5.43.10 are affected by CVE-2026-8376.
What type of vulnerability is CVE-2026-8376?
CVE-2026-8376 is classified as a buffer overflow vulnerability.
On which builds is CVE-2026-8376 a concern?
CVE-2026-8376 is a concern specifically on 32-bit builds of Perl.