Security Advisories (1)
CVE-2026-15534 (2026-08-09)

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it. A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.

NAME

App::Prove::State - State storage for the prove command.

VERSION

Version 3.52

DESCRIPTION

The prove command supports a --state option that instructs it to store persistent state across runs. This module implements that state and the operations that may be performed on it.

SYNOPSIS

# Re-run failed tests
$ prove --state=failed,save -rbv

METHODS

Class Methods

new

Accepts a hashref with the following key/value pairs:

  • store

    The filename of the data store holding the data that App::Prove::State reads.

  • extensions (optional)

    The test name extensions. Defaults to .t.

  • result_class (optional)

    The name of the result_class. Defaults to App::Prove::State::Result.

result_class

Getter/setter for the name of the class used for tracking test results. This class should either subclass from App::Prove::State::Result or provide an identical interface.

extensions

Get or set the list of extensions that files must have in order to be considered tests. Defaults to ['.t'].

results

Get the results of the last test run. Returns a result_class() instance.

commit

Save the test results. Should be called after all tests have run.

Instance Methods

apply_switch

$self->apply_switch('failed,save');

Apply a list of switch options to the state, updating the internal object state as a result. Nothing is returned.

Diagnostics: - "Illegal state option: %s"

last

Run in the same order as last time

failed

Run only the failed tests from last time

passed

Run only the passed tests from last time

all

Run all tests in normal order

hot

Run the tests that most recently failed first

todo

Run the tests ordered by number of todos.

slow

Run the tests in slowest to fastest order.

fast

Run test tests in fastest to slowest order.

new

Run the tests in newest to oldest order.

old

Run the tests in oldest to newest order.

save

Save the state on exit.

get_tests

Given a list of args get the names of tests that should run

observe_test

Store the results of a test.

save

Write the state to a file.

load

Load the state from a file