Shared Directory Vulnerability in Data::RoaringBitmap::Shared for Perl
CVE-2026-65065

Currently unrated

Key Information:

Vendor

Egor

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65065?

The Data::RoaringBitmap::Shared module for Perl prior to version 0.02 exposes a significant vulnerability by creating a world-readable mmap backing file without proper restrictions. The file, generated with permissions that allow any local user to read it, can be manipulated through symbolic links that redirect its path, leading to unauthorized access to Inter-Process Communication (IPC) payloads. By exploiting this oversight, a local attacker can bypass standard security mechanisms, posing a serious risk to data integrity and confidentiality in environments where this module is deployed.

Affected Version(s)

Data::RoaringBitmap::Shared 0 < 0.02

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.