CVE-2024-14031 Details
Description
Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
A buffer overwrite vulnerability has been identified in Sereal::Encoder versions 4.000 through 4.009_002 for Perl. This issue arises from a race condition in the one-pass compression functions of the embedded Zstandard library, prior to version 1.3.8. The vulnerability allows an attacker to write bytes out of bounds by using an output buffer smaller than the recommended size.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/advisories/GHSA-w77f-wv46-4vcx | CPANSec | Not Applicable |
| https://metacpan.org/release/YVES/Sereal-Encoder-4.010/changes | CPANSec | Release Notes |
| https://www.cve.org/CVERecord?id=CVE-2019-11922 | CPANSec | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| yves sereal::encoder | >= 4.000, < 4.010 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | CPANSec |
| Apr 13, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | CVE Modified | CPANSec |
| Mar 31, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | New CVE Received | CPANSec |