commit 6dee593a198a5f07b1e18f9d7143f1ef5bbf84ff Author: Robert Rothenberg Date: Tue Sep 29 22:43:31 2026 +0100 Fix CVE-2026-80490 If the input is not stringified when SvCUR is called, then the string will be initialised garbage data, and potentially from an out-of-bounds read. This can happen when the input is actually a blessed object, or is a number. See https://rt.cpan.org/Ticket/Display.html?id=181560 Assisted-by: Claude Opus 5.5 (1M context) Signed-off-by: Robert Rothenberg diff --git a/t/segfault.t b/t/segfault.t new file mode 100644 index 0000000..691d453 --- /dev/null +++ b/t/segfault.t @@ -0,0 +1,44 @@ +package Foo; + +use strict; +use warnings; + +use overload '""' => sub { + my ($self) = @_; + join( "", @$self ); +}; + +sub new { + my $class = shift; + bless [ @_ ], $class; +} + + +package main; + +use strict; +use warnings; + +use Test::More 0.96; + +use Algorithm::AhoCorasick::XS; + +subtest "CVE-2026-80490 (object)" => sub { + + my $ac = Algorithm::AhoCorasick::XS->new( [ 11, 22 ] ); + + my $obj = Foo->new(211); + is "$obj", "211", "stringified"; + + is $ac->first_match( $obj ) => 11; + +}; + +subtest "CVE-2026-80490 (num)" => sub { + + my $ac = Algorithm::AhoCorasick::XS->new( [ 11, 22 ] ); + is $ac->first_match( 211 ) => 11; + +}; + +done_testing; diff --git a/typemap b/typemap index 2bf6336..68bcc45 100644 --- a/typemap +++ b/typemap @@ -11,7 +11,9 @@ T_STD_STRING if (!SvOK($arg)) { $var = std::string(); } else { - $var = std::string(SvPV_nolen($arg), SvCUR($arg)); + STRLEN len; + const char *p = SvPV($arg,len); + $var = std::string(p,len); } // From ExtUtils::Typemap::STL::Vector.