DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders.
The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl-dbi | Jul 28, 2026 | Jun 5, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-DBI-debuginfoUpgrade perl-DBI | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-DBI-debugsourceUpgrade perl-DBIUpgrade perl-DBI-testsUpgrade perl-DBI-debuginfo | Jun 23, 2026 | Jun 5, 2026 |
| Debian | — | Upgrade libdbi-perl | Jun 16, 2026 | Jun 16, 2026 |
| Redhat_linux | — | No solution existsUpgrade perl-DBI-debuginfoUpgrade perl-DBI-debugsourceUpgrade perl-DBI | Jul 17, 2026 | Jun 5, 2026 |
| Rocky_linux | — | Upgrade perl-DBI-debuginfoUpgrade perl-DBI-debugsourceUpgrade perl-DBI | Jul 20, 2026 | Jul 15, 2026 |
| Ubuntu | — | Upgrade libdbi-perl (Ubuntu Pro)Upgrade libdbi-perl | Jun 25, 2026 | Jun 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub