CVE-2026-7111

Public on 2026-04-29
Modified on 2026-05-02
Description
CSV_XS versions before 1.62 for Perl have a use-after-free when
registered callbacks extend the Perl argument stack, which may enable
type confusion or memory corruption.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core perl-Text-CSV_XS Not Affected
Amazon Linux 2023 perl-Text-CSV_XS Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H