Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-60082

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

A flaw was found in perl-DBI, a database interface for Perl. This vulnerability arises when the DBI library processes inconsistent data, specifically when a statement handle lacks fields but is associated with a non-empty data row. This inconsistency can cause the internal row-buffer to attempt reading from an invalid memory location, an out-of-bounds read. An attacker could exploit this by supplying malformed metadata and rows to the prepare method, potentially leading to application instability or a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perl-DBIFix deferred
Red Hat Enterprise Linux 6perl-DBIOut of support scope
Red Hat Enterprise Linux 7perl-DBIOut of support scope
Red Hat Enterprise Linux 8perl-DBIFix deferred
Red Hat Enterprise Linux 8perl-DBI:1.641/perl-DBIFix deferred
Red Hat Enterprise Linux 9perl-DBIFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2500019perl-DBI: perl-DBI: Denial of Service via out-of-bounds read

EPSS

Процентиль: 31%
0.00387
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
18 дней назад

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

CVSS3: 9.1
nvd
18 дней назад

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

CVSS3: 9.1
msrc
12 дней назад

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row

CVSS3: 9.1
debian
18 дней назад

DBI versions before 1.651 for Perl do not enforce statement handle con ...

suse-cvrf
11 дней назад

Security update for perl-DBI

EPSS

Процентиль: 31%
0.00387
Низкий

3.3 Low

CVSS3