Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10879

Опубликовано: 05 июн. 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.

A flaw was found in perl-DBI. A heap overflow vulnerability exists when preparsing SQL statements with more than 9 binders. The preparse method incorrectly allocates buffer space for SQL placeholder characters, leading to an overflow when processing binders with two or more digits. This can result in a denial of service or potentially arbitrary code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perl-DBIAffected
Red Hat Enterprise Linux 7perl-DBIAffected
Red Hat Enterprise Linux 8perl-DBIAffected
Red Hat Enterprise Linux 10perl-DBIFixedRHSA-2026:3851313.07.2026
Red Hat Enterprise Linux 8perl-DBIFixedRHSA-2026:3890113.07.2026
Red Hat Enterprise Linux 9perl-DBIFixedRHSA-2026:3851213.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2485464perl-DBI: perl-DBI: Heap overflow in SQL preparsing can lead to denial of service or arbitrary code execution.

EPSS

Процентиль: 39%
0.00485
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 месяцев назад

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.

CVSS3: 9.8
nvd
около 2 месяцев назад

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.

CVSS3: 8.6
msrc
около 2 месяцев назад

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders

CVSS3: 9.8
debian
около 2 месяцев назад

DBI versions before 1.648 for Perl have a heap overflow when preparsin ...

CVSS3: 9.8
github
около 2 месяцев назад

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.

EPSS

Процентиль: 39%
0.00485
Низкий

7.7 High

CVSS3