CPANSA-DBI-2026-60082: DBI vulnerability

Publisher giterlizzi Document category csaf_security_advisory
Initial release date 2026-07-14T00:00:00 Engine CSAF Perl Toolkit 0.26
Current release date 2026-07-14T00:00:00 Build Date
Current version 1 Status final
CVSS v3.1 Base Score 9.1 Severity
Original language Language en
Also referred to

Vulnerability Description

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

Vulnerabilities

CVE-2026-60082

Vulnerability Description

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.

When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.

This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

Weakness CWE-125 : Out-of-bounds Read

Product status

Known affected
Product Score
DBI less than 1.651
CVSS Version CVSS Vector CVSS Base Score CVSS Base Severity
3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H 9.1 Critical
Fixed

giterlizzi

Namespace: https://github.com/giterlizzi/

gdt@cpan.org

References

Revision history

Version Date of the revision Summary of the revision
1 Tue Jul 14 00:00:00 2026 First release

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/