PatchSiren

SMUELLER CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review SMUELLER CVE published 2026-10-10

CVE-2026-107794

A vulnerability in ExtUtils::Typemaps::STL::List versions before 1.07 for Perl can lead to memory exhaustion due to the allocation of a 32 GiB array on an empty list. This occurs when the OUTPUT typemaps call av_extend( av, len-1 ) on an empty list, resulting in an underflow and allocation of an array with 2^32 slots. Defenders should assess exposure and prioritize verification and remediation of Perl app [truncated]

Review SMUELLER CVE published 2026-10-10

CVE-2026-107373

CVE-2026-107373 debrief: ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. This issue arises from the typemap's use of $var = std::string( SvPV_nolen($arg), SvCUR($arg) ), where evaluation order for C++ arguments is unspecified. Some compilers may evaluate SvCUR($arg) first, leading to potential invalid values when $ [truncated]

Review SMUELLER CVE published 2026-10-10

CVE-2013-10076

A vulnerability in ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl can lead to memory exhaustion due to the allocation of a 32 GiB array on an empty list. This occurs when the OUTPUT typemaps call av_extend( av, len-1 ) on an empty list, resulting in an underflow and the allocation of an array with 2^32 slots. Defenders should assess exposure and prioritize upgrading to version 1.05 or later [truncated]