Описание
ELSA-2026-49514: perl-DBI security update (IMPORTANT)
[1.643-26.3]
- Fix CVE-2026-14380: unsafe string eval in DBI::Profile
- Resolves: RHEL-211146
[1.643-26.2]
- Fix CVE-2026-14739: set a hard limit of 99999 on '?' placeholders
- Resolves: RHEL-193293
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
perl-DBI
1.643-26.el10_2.3
Oracle Linux x86_64
perl-DBI
1.643-26.el10_2.3
Связанные CVE
Связанные уязвимости
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.