What is CVE-2026-65068?
In Data::SpatialHash::Shared for Perl versions before 0.02, the mmap backing file is created with world-readable permissions (mode 0666, resulting in 0644 under default umask) and opened without O_EXCL or O_NOFOLLOW, potentially exposing sensitive data. Affected systems should immediately upgrade to version 0.02 or later.
Azərbaycanca: CVE-2026-65068 Perl-in Data::SpatialHash::Shared modulunun 0.02-dən əvvəlki versiyalarında mmap backing faylının dünya tərəfindən oxuna bilən (world-readable) yaradılması və O_EXCL/O_NOFOLLOW olmadan açılması səbəbindən məxfi məlumatların ifşasına yol açır. Bu zəiflik həmin moduldan istifadə edən sistemləri təsirləyir və təcili olaraq 0.02 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-732
FAQ2
Which versions of Data::SpatialHash::Shared are vulnerable to CVE-2026-65068?
Versions of the module before 0.02 are affected by this vulnerability.
What action is required to remediate CVE-2026-65068?
Affected systems should immediately upgrade to version 0.02 or later of the Data::SpatialHash::Shared module.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.