SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-65067

LOW · CVSS 3.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The vulnerability affects Data::Intern::Shared versions prior to 0.02 for Perl, which creates a world-readable memory-mapped file in shared directories like /tmp or /dev/shm, allowing local users to access sensitive IPC payloads. The absence of O_EXCL and O_NOFOLLOW flags enables an attacker to exploit symlinks or pre-existing files, leading to potential data exposure or manipulation. Organizations using affected versions of this library should prioritize patching to mitigate the risk of local privilege escalation and data leakage.

CVE
CVE-2026-65067
Severity
LOW
CVSS
3.8
EPSS
0.12%

Original NVD Description

Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.