perl-DBI:1.641 security update

エラータID: AXSA:2026-1570:01

Release date: 
Wednesday, August 19, 2026 - 14:49
Subject: 
perl-DBI:1.641 security update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The perl-DBI package provides the standard database interface module for the
Perl programming language. It implements a database-independent interface,
meaning it defines a consistent set of methods, variables, and conventions for
database operations.

Security Fix(es):

* DBI: Heap overflow when preparsing SQL statements with excessive placeholders (CVE-2026-14739)
* DBI: Arbitrary code execution via caller-influenced Profile attribute (CVE-2026-14380)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-14380
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.
CVE-2026-14739
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.

Modularity name: "perl-DBI"
Stream name: "1.641"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. perl-DBI-1.641-8.module+el8+2028+11ecfa2e.src.rpm
    MD5: 655dac8e02335dbf632c0be9a5225229
    SHA-256: e0af5796208678d5ca2dcf682f34b3963b207e36ead8c584601b02884be133ae
    Size: 619.13 kB

Asianux Server 8 for x86_64
  1. perl-DBI-1.641-8.module+el8+2028+11ecfa2e.x86_64.rpm
    MD5: 63561ca48152d220ee0d5ba2e5354e99
    SHA-256: bad5728ae1cc24fc82ee8cb0bb27596e2f91e729d33eea9d22e8a992a3276e8a
    Size: 739.98 kB
  2. perl-DBI-debugsource-1.641-8.module+el8+2028+11ecfa2e.x86_64.rpm
    MD5: 30dcbaaf961e471e44f5aa3737064e4a
    SHA-256: d0fbbf5e1ec5c26910c7e1e79b0522306328f8cc684bdde37b37778481561ff9
    Size: 122.39 kB