Security Advisories (1)
CVE-2026-57433
(2026-07-13)
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.
No POD found for weak.t.
Time to read the source?
Module Install Instructions
To install Storable, copy and paste the appropriate command in to your terminal.
cpanm Storable
perl -MCPAN -e shell
install Storable
For more information on module installation, please visit the detailed CPAN module installation guide.