Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9698

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.

A flaw was found in DBI, a Perl database interface. This vulnerability allows an attacker to trigger a buffer overflow by manipulating error messages within an application. When specific error handling options are active, an attacker can provide oversized error text, which may lead to arbitrary code execution or a denial of service (DoS).

Отчет

Exploitation of this vulnerability requires that an attacker can provide values to an endpoint using perl-DBI which trigger certain errors. The attacker has no means of directly controlling the location and thus consequences of the buffer overflow, making the most likely outcome a denial-of-service due to corruption of the application's memory.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Users are advised to identify network-accessible applications which use perl-DBI and ensure that only trusted users have access to those applications.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perl-DBIOut of support scope
Red Hat Enterprise Linux 7perl-DBIAffected
Red Hat Enterprise Linux 8perl-DBIAffected
Red Hat Enterprise Linux 10perl-DBIFixedRHSA-2026:3851313.07.2026
Red Hat Enterprise Linux 8perl-DBIFixedRHSA-2026:3890113.07.2026
Red Hat Enterprise Linux 9perl-DBIFixedRHSA-2026:3851213.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2486734DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution

EPSS

Процентиль: 37%
0.00452
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 месяцев назад

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.

CVSS3: 9.8
nvd
около 2 месяцев назад

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.

CVSS3: 8.8
msrc
около 1 месяца назад

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer

CVSS3: 9.8
debian
около 2 месяцев назад

DBI versions before 1.648 for Perl saved errors in a limited-sized buf ...

suse-cvrf
28 дней назад

Security update for perl-DBI

EPSS

Процентиль: 37%
0.00452
Низкий

8.2 High

CVSS3

Уязвимость CVE-2026-9698