An oss-sec advisory highlighted CVE-2017-20230 in Perl's Storable module, where versions before 3.05 contain a stack-based buffer overflow in retrieve_hook. The flaw occurs because a class-name length is stored in a signed integer and later handled as unsigned during read operations, allowing crafted serialized data to trigger the overflow. The issue was patched shortly after disclosure and fixed in Storable 3.05, with later inclusion in Perl through newer bundled releases.
Follow-up discussion on oss-sec questioned the practical security impact and even the usefulness of the CVE because Storable documentation already warns that it is unsafe for untrusted input. Participants pointed to earlier deserialization concerns, including CVE-2015-1592, and debated whether malformed local Storable files should continue to receive CVE treatment given the module's longstanding security warning and lack of a safe mode for hostile data.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-21, oss-sec participants revisited CVE-2017-20230 and questioned its practical significance because Storable documentation already warns it is unsafe for untrusted input. The discussion referenced prior related concerns such as CVE-2015-1592 and debated whether assigning a CVE was meaningful in this context.
The issue was later assigned the identifier CPANSA-Storable-2017-01 on 2018-10-06. This formalized the advisory record for the Storable vulnerability.
The vulnerability was addressed in the release of Storable 3.05 on 2017-01-29. Users were advised to upgrade to version 3.05 or newer.
A fix for the Storable stack overflow issue was made on 2017-01-25. The remediation corrected the length-handling bug that could be triggered by crafted serialized data.
A stack overflow vulnerability in Perl's Storable module was reported on 2017-01-24. The flaw was caused by retrieve_hook storing a class-name length as a signed integer and later treating it as unsigned during reads.
The Storable fix was later incorporated into Perl v5.27.9 through inclusion of Storable 3.06. This extended the remediation into the broader Perl distribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.