CPANSA-DBI-2026-88815: DBI vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-09-28T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-09-28T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 6.2 | Severity | Medium |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.
When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.
This is reachable in Perl using the sql_type_cast function:
my $num = 42;
DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );
Vulnerabilities
CVE-2026-88815
Vulnerability DescriptionDBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.
When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.
This is reachable in Perl using the sql_type_cast function:
my $num = 42;
DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );
| Weakness | CWE-843 : Access of Resource Using Incompatible Type ('Type Confusion') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| DBI less than 1.654 |
|
Fixed
- DBI greater than or equal 1.654
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-DBI-2026-88815 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-dbi-2026-88815.json - https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d6702.patch external
https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d6702.patch - https://github.com/perl5-dbi/dbi/security/advisories/GHSA-c8vq-w3wr-6979 external
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-c8vq-w3wr-6979 - https://metacpan.org/release/HMBRAND/DBI-1.654/changes external
https://metacpan.org/release/HMBRAND/DBI-1.654/changes - http://www.openwall.com/lists/oss-security/2026/09/28/12 external
http://www.openwall.com/lists/oss-security/2026/09/28/12 - https://github.com/perl5-dbi/dbi/security/advisories/GHSA-c8vq-w3wr-6979 external
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-c8vq-w3wr-6979 - CVE-2026-88815 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-88815
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Mon Sep 28 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/