Buffer Overflow Vulnerability in Sereal::Encoder for Perl
CVE-2024-14031

8.1HIGH

Key Information:

Vendor

Yves

Vendor
CVE Published:
31 March 2026

What is CVE-2024-14031?

Sereal::Encoder versions ranging from 4.000 to 4.009_002 for Perl are affected by a buffer overwrite vulnerability linked to its embedded Zstandard library. This flaw stems from a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8. Attackers could exploit this vulnerability by supplying an output buffer that is smaller than the recommended size, allowing them to potentially write bytes beyond the bounds of the allocated memory, leading to unintended behavior or execution of arbitrary code.

Affected Version(s)

Sereal::Encoder 4.000 <= 4.009_002

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.