perl-DBI:1.641 security update

エラータID: AXSA:2026-1571:01

Release date: 
Wednesday, August 19, 2026 - 15:38
Subject: 
perl-DBI:1.641 security update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The perl-DBI package provides the standard database interface module for the
Perl programming language. It implements a database-independent interface,
meaning it defines a consistent set of methods, variables, and conventions for
database operations.

Security Fix(es):

* DBI: Heap overflow when preparsing SQL statements with excessive
placeholders (CVE-2026-14739)
* DBI: Arbitrary code execution via caller-influenced Profile attribute
(CVE-2026-14380)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE-2026-14380
DBI versions before 1.650 for Perl are vulnerable to code injection via
caller-influenced Profile. When a string is assigned to a DBI handle's Profile
attribute, DBI splits it into path, package and arguments, and interpolates the
package part in a string eval with no validation of the package name. Any
caller-influenced value that reaches the Profile attribute is therefore
arbitrary Perl code execution, including calls to run system commands. The
Profile attribute can be set from three different sources that can carry
untrusted data: the DBI_PROFILE environment variable, a direct attribute
assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An
attacker controlling any of those inputs runs arbitrary Perl in the host
process. The strongest remote position is a network-exposed DBI::Gofer /
DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a
client execute code on the broker host.
CVE-2026-14739
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL
statements with an extreme number of placeholders. The fix for CVE-2026-10879
did not allocate enough memory to handle approximately 1.2-million placeholders.
DBI version 1.650 sets a hard limit of 99,999 placeholders.

Modularity name: "perl-DBI"
Stream name: "1.641"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. perl-DBI-1.641-8.module+el8+2028+9b045779.src.rpm
    MD5: 883f58169b489502314d6c488c03630b
    SHA-256: 58bc8e262a6062463a1e510e4fcf1178f4a2faf0ef1dc658275aca85a9a2a30d
    Size: 619.13 kB

Asianux Server 8 for x86_64
  1. perl-DBI-1.641-8.module+el8+2028+9b045779.x86_64.rpm
    MD5: 1ce2813258cecd298f0bb8cfb6759407
    SHA-256: 8b81f9c22f537f3584de4268fa83fb9a7956491aaba09d79d598b65ca2b938c9
    Size: 739.32 kB
  2. perl-DBI-debugsource-1.641-8.module+el8+2028+9b045779.x86_64.rpm
    MD5: 73950e738a35d97a4743bb94522e6865
    SHA-256: dd67c23d8a1e2d43552d292d489e9d6b15fe7c51800862f11e87f3b01623123c
    Size: 122.39 kB