DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.
When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.
This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl-dbi | Jul 28, 2026 | Jul 14, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-DBI-debuginfoUpgrade perl-DBI | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-DBIUpgrade perl-DBI-debuginfoUpgrade perl-DBI-debugsourceUpgrade perl-DBI-tests | Aug 10, 2026 | Jul 14, 2026 |
| Debian | — | Upgrade libdbi-perl | Aug 30, 2026 | Aug 30, 2026 |
| Redhat_linux | — | No solution exists | Jul 20, 2026 | Jul 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub