Vulnerability Description
Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://metacpan.org/release/EGOR/Data-PubSub-Shared-0.07/changes
- https://metacpan.org/release/EGOR/Data-PubSub-Shared-0.07/diff/EGOR/Data-PubSub-
FAQ
What is CVE-2026-64617?
CVE-2026-64617 is a vulnerability with a CVSS score of 3.8 (LOW). Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h with open(path, O_RDWR|O_CREA...
How severe is CVE-2026-64617?
CVE-2026-64617 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-64617?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.