SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64616

LOW · CVSS 3.3 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The vulnerability affects Data::NDArray::Shared versions prior to 0.02 for Perl, allowing local users to exploit a world-readable memory-mapped file created without proper access controls. This can lead to unauthorized access to sensitive IPC payloads and potential manipulation of files through symlink attacks. Organizations using this Perl module should prioritize remediation to mitigate the risk of local privilege escalation and data exposure.

CVE
CVE-2026-64616
Severity
LOW
CVSS
3.3
EPSS
0.12%

Original NVD Description

Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.