Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws.
When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a signed integer overflow in the size calculation passed to Renew().
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-17 19:16
Updated : 2026-06-17 11:04
NVD link : CVE-2026-8507
Mitre link : CVE-2026-8507
CVE.ORG link : CVE-2026-8507
JSON object : View
Products Affected
No product.
CWE
CWE-787
Out-of-bounds Write
