What is CVE-2026-65066?
Data::RingBuffer::Shared for Perl before version 0.04 creates a world-readable mmap backing file without using O_EXCL or O_NOFOLLOW. This could allow a local attacker to read sensitive data from the shared memory segment. Update the module to version 0.04 or later.
Azərbaycanca: Perl üçün Data::RingBuffer::Shared modulunun 0.04-dən əvvəlki versiyalarında mmap dəstək faylı dünya tərəfindən oxuna bilən (world-readable) yaradılır və O_EXCL və ya O_NOFOLLOW olmadan açılır. Bu, lokal təcavüzkara həssas məlumatları oxumağa imkan verə bilər. Modul ən azı 0.04 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-732
FAQ1
Which versions of the Data::RingBuffer::Shared module are affected by CVE-2026-65066?
Versions of Data::RingBuffer::Shared for Perl before 0.04 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.