Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:49514

Опубликовано: 04 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: perl-DBI security update

DBI is a database access Application Programming Interface (API) for the Perl Language. The DBI API Specification defines a set of functions, variables and conventions that provide a consistent database interface independent of the actual database being used.

Security Fix(es):

  • DBI: DBI: Arbitrary code execution via caller-influenced Profile attribute (CVE-2026-14380)

  • DBI: DBI: Heap overflow when preparsing SQL statements with excessive placeholders (CVE-2026-14739)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
perl-DBIaarch6426.el10_2.3perl-DBI-1.643-26.el10_2.3.aarch64.rpm
perl-DBIx86_6426.el10_2.3perl-DBI-1.643-26.el10_2.3.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

rocky
7 дней назад

Important: perl-DBI security update

oracle-oval
8 дней назад

ELSA-2026-49612: perl-DBI security update (IMPORTANT)

oracle-oval
8 дней назад

ELSA-2026-49514: perl-DBI security update (IMPORTANT)

CVSS3: 9.8
ubuntu
около 1 месяца назад

DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.

CVSS3: 8.1
redhat
около 1 месяца назад

DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.