Vulnerability Description
Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it then trusts. rdx_find_locked indexes nodes[cur].children[k] and reads each node's label_off and label_len raw from the mmap'd segment, none bounded against the node count or the arena size. A local peer that can write the backing file can leave the header valid while poisoning the node records, so a lookup dereferences an out-of-bounds node or arena index, reading adjacent memory or crashing the process.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://metacpan.org/release/EGOR/Data-RadixTree-Shared-0.02/changes
- https://metacpan.org/release/EGOR/Data-RadixTree-Shared-0.02/diff/EGOR/Data-Radi
FAQ
What is CVE-2026-59141?
CVE-2026-59141 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the h...
How severe is CVE-2026-59141?
CVE-2026-59141 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-59141?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.