What is CVE-2026-64617?
CVE-2026-64617 affects Data::PubSub::Shared for Perl versions prior to 0.07, where a world-readable mmap backing file is created and opened without O_EXCL or O_NOFOLLOW flags. This may allow a local attacker to read sensitive shared memory contents. Upgrading to version 0.07 or later is recommended.
Azərbaycanca: CVE-2026-64617, Perl üçün Data::PubSub::Shared modulunun 0.07-dən əvvəlki versiyalarında aşkarlanıb. Bu zəiflik mmap dəstək faylının dünya tərəfindən oxuna bilən (world-readable) yaradılmasına və faylın `O_EXCL` və ya `O_NOFOLLOW` bayraqları olmadan açılmasına səbəb olur, bu da lokal təcavüzkarın həssas məlumatları oxumasına imkan verə bilər. Modulu 0.07 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which software module is affected by CVE-2026-64617?
The vulnerability affects Data::PubSub::Shared for Perl versions prior to 0.07.
What risk arises from exploiting CVE-2026-64617?
A local attacker may read sensitive shared memory contents because the mmap backing file is created world-readable.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.