CVE-2026-65068 Details
Description
Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
A vulnerability exists in Data::SpatialHash::Shared for Perl, affecting versions prior to 0.02. The issue arises because the software creates a world-readable memory-mapped file without proper safeguards, allowing local users to access sensitive inter-process communication data. The file is generated with default permissions that make it readable by all users, and the absence of certain flags when opening the file creates a risk of following malicious symlinks or unintentionally using pre-existing files. This vulnerability can be exploited by placing a symlink or file at the path where the mmap segment is created, taking advantage of the lack of exclusive and symlink-following protections.
Users can update to Data::SpatialHash::Shared version 0.02 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://metacpan.org/release/EGOR/Data-SpatialHash-Shared-0.02/changes | CPANSec | Vendor |
| https://metacpan.org/release/EGOR/Data-SpatialHash-Shared-0.02/diff/EGOR/Data-SpatialHash-Shared-0.01#sphash.h | CPANSec | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | CPANSec |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | CPANSec |
Affected Products
| Product | Versions |
|---|---|
| Data::SpatialHash::Shared | < 0.02 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | CPANSec |
Volerion