Out-of-Bounds Access in Data::SpatialHash::Shared for Perl
CVE-2026-59146

Currently unrated

Key Information:

Vendor

Egor

Vendor
CVE Published:
21 July 2026

What is CVE-2026-59146?

The Data::SpatialHash::Shared component for Perl suffers from a severe issue where it permits out-of-bounds reads and writes due to unvalidated indices. This vulnerability arises in the functions sph_walk_cell and sph_alloc_slot, where untrusted data may lead to memory corruption or process crashes. A local user with write access to the backing file can exploit this flaw by manipulating the bucket chain and free list, resulting in unexpected behavior when querying or inserting data.

Affected Version(s)

Data::SpatialHash::Shared 0 < 0.02

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.