Out-of-Bounds Access in Data::SpatialHash::Shared for Perl
CVE-2026-59146
Currently unrated
What is CVE-2026-59146?
The Data::SpatialHash::Shared component for Perl suffers from a severe issue where it permits out-of-bounds reads and writes due to unvalidated indices. This vulnerability arises in the functions sph_walk_cell and sph_alloc_slot, where untrusted data may lead to memory corruption or process crashes. A local user with write access to the backing file can exploit this flaw by manipulating the bucket chain and free list, resulting in unexpected behavior when querying or inserting data.
Affected Version(s)
Data::SpatialHash::Shared 0 < 0.02
