What is CVE-2026-59146?
CVE-2026-59146 is an out-of-bounds read and write vulnerability in the Data::SpatialHash::Shared library for Perl before version 0.02. It occurs due to unvalidated bucket, link, and free-list indices in the sph_walk_cell and sph_alloc_slot functions. Users should upgrade to version 0.02 or later.
Azərbaycanca: CVE-2026-59146, Perl üçün Data::SpatialHash::Shared kitabxanasının 0.02-dən əvvəlki versiyalarında out-of-bounds oxuma və yazma zəifliyidir. Bu, sph_walk_cell və sph_alloc_slot funksiyalarında doğrulanmamış indekslər səbəbindən baş verir. İstifadəçilər kitabxananı ən az 0.02 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which functions are affected by CVE-2026-59146?
The out-of-bounds read and write vulnerability occurs due to unvalidated bucket, link, and free-list indices in the sph_walk_cell and sph_alloc_slot functions.
To which version should users upgrade Data::SpatialHash::Shared to fix CVE-2026-59146?
Users should upgrade to version 0.02 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.