Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-14740

Опубликовано: 07 июл. 2026
Источник: debian

Описание

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libdbi-perlfixed1.650-1package
libdbi-perlno-dsatrixiepackage
libdbi-perlpostponedbookwormpackage
libdbi-perlpostponedbullseyepackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/41625532/

  • https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg

  • Fixed by: https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01 (1.650)

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 месяца назад

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

CVSS3: 5
redhat
около 1 месяца назад

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

CVSS3: 9.1
nvd
около 1 месяца назад

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

CVSS3: 9.1
msrc
около 1 месяца назад

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment

suse-cvrf
около 1 месяца назад

Security update for perl-DBI