What is CVE-2026-65065?
CVE-2026-65065 is a vulnerability in Data::RoaringBitmap::Shared for Perl versions before 0.02, where an mmap backing file is created with world-readable permissions (mode 0666) and opened without O_EXCL or O_NOFOLLOW flags. This could allow a local attacker to read sensitive data. Users should upgrade to the latest version.
Azərbaycanca: CVE-2026-65065, Perl üçün Data::RoaringBitmap::Shared modulunun 0.02-dən əvvəlki versiyalarında mmap ilə yaradılan arxa faylın icazələrinin dünya tərəfindən oxuna bilən (world-readable) olmasına və O_EXCL/O_NOFOLLOW bayraqları olmadan açılmasına səbəb olan zəiflikdir. Bu, lokal hücumçuya həssas məlumatları oxumağa imkan verə bilər. İstifadəçilər modulu ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-732
FAQ2
Which software module is affected by CVE-2026-65065?
CVE-2026-65065 affects the Data::RoaringBitmap::Shared module for Perl versions before 0.02.
What does this vulnerability allow a local attacker to do?
This vulnerability could allow a local attacker to read sensitive data because the mmap backing file is created with world-readable permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.