World-Readable Backing File Vulnerability in Perl's Data::Buffer::Shared
CVE-2026-64613

Currently unrated

Key Information:

Vendor

Egor

Vendor
CVE Published:
21 July 2026

What is CVE-2026-64613?

The Data::Buffer::Shared module for Perl prior to version 0.05 is susceptible to a vulnerability that allows local users to access sensitive information. Due to the configuration of mmap backing files, a world-readable segment is created without the O_NOFOLLOW option, potentially allowing unauthorized access to IPC payloads. This vulnerability arises when files are created with default permissions, leading to a scenario where symlink redirections can further compromise data security in shared directories such as /tmp or /dev/shm.

Affected Version(s)

Data::Buffer::Shared 0 < 0.05

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.