What is CVE-2026-59143?
Data::RoaringBitmap::Shared versions before 0.02 for Perl are vulnerable to an out-of-bounds read via an unvalidated container offset and cardinality in `rb_contains_locked`. This issue occurs because the attach-time validator `rb_validate_header` lacks proper validation of these fields despite checking header scalars and region layout against file size. Upgrading to version 0.02 or later is recommended to mitigate the risk.
Azərbaycanca: Perl üçün Data::RoaringBitmap::Shared modulunun 0.02-dən əvvəlki versiyalarında `rb_contains_locked` funksiyasında `out-of-bounds read` zəifliyi aşkarlanıb. Bu problem, fayl ölçüsü yoxlanılsa da, konteyner ofset və kardinallığın düzgün yoxlanılmaması səbəbindən yaranır. Modulun 0.02 və ya daha yeni versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
In which function of the Data::RoaringBitmap::Shared module for Perl was CVE-2026-59143 discovered?
CVE-2026-59143 was discovered as an out-of-bounds read in the `rb_contains_locked` function.
To which version should the module be upgraded to mitigate CVE-2026-59143?
Upgrading to version 0.02 or later is recommended to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.