{"id":"DEBIAN-CVE-2026-8463","details":"Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input.  The auto-detect form of argon2_verify passes encoded_len - 1 as the length argument to memchr without checking that encoded_len is non-zero. When the encoded string is empty, the size_t subtraction underflows to SIZE_MAX and memchr scans adjacent heap memory looking for a '$' separator byte.  A caller that invokes argon2_verify against a stored hash that may legitimately be empty (for example a placeholder row or a NULL column materialised as an empty string) reads out-of-bounds heap memory, which can crash the process or leak the position of an adjacent '$' byte into subsequent parsing.","modified":"2026-09-14T17:03:37.833196589Z","published":"2026-05-13T14:18:17.140Z","upstream":["CVE-2026-8463"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-8463"}],"affected":[{"package":{"name":"libcrypt-argon2-perl","ecosystem":"Debian:12","purl":"pkg:deb/debian/libcrypt-argon2-perl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.013-1","0.020-1","0.022-1","0.026-1","0.029-1","0.030-1","0.031-1","0.032-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-8463.json"}},{"package":{"name":"libcrypt-argon2-perl","ecosystem":"Debian:13","purl":"pkg:deb/debian/libcrypt-argon2-perl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.030-1","0.031-1","0.032-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-8463.json"}},{"package":{"name":"libcrypt-argon2-perl","ecosystem":"Debian:14","purl":"pkg:deb/debian/libcrypt-argon2-perl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.031-1"}]}],"versions":["0.030-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-8463.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}