CyberRota Analysis
AI-GeneratedA signed integer overflow vulnerability exists in Storable versions prior to 3.41 for Perl, specifically when deserializing crafted SX_HOOK records. This flaw allows an attacker to trigger a panic in the application, leading to a denial of service during the deserialization process. Organizations using affected versions of Storable should prioritize patching this vulnerability due to its critical severity and potential impact on application stability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.
Related CVEs
Other vulnerabilities affecting the same vendor(s)