"perl-DBI":"1.641" perl-DBI-1.641-8.module+el8+2028+f328b067
エラータID: AXSA:2026-1574:01
The perl-DBI package provides the standard database interface module for the
Perl programming language. It implements a database-independent interface,
meaning it defines a consistent set of methods, variables, and conventions for
database operations.
Security Fix(es):
* DBI: Heap overflow when preparsing SQL statements with excessive
placeholders (CVE-2026-14739)
* DBI: Arbitrary code execution via caller-influenced Profile attribute
(CVE-2026-14380)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE-2026-14380
DBI versions before 1.650 for Perl are vulnerable to code injection via
caller-influenced Profile. When a string is assigned to a DBI handle's Profile
attribute, DBI splits it into path, package and arguments, and interpolates the
package part in a string eval with no validation of the package name. Any
caller-influenced value that reaches the Profile attribute is therefore
arbitrary Perl code execution, including calls to run system commands. The
Profile attribute can be set from three different sources that can carry
untrusted data: the DBI_PROFILE environment variable, a direct attribute
assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An
attacker controlling any of those inputs runs arbitrary Perl in the host
process. The strongest remote position is a network-exposed DBI::Gofer /
DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a
client execute code on the broker host.
CVE-2026-14739
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL
statements with an extreme number of placeholders. The fix for CVE-2026-10879
did not allocate enough memory to handle approximately 1.2-million placeholders.
DBI version 1.650 sets a hard limit of 99,999 placeholders.
Modularity name: "perl-DBI"
Stream name: "1.641"
Update packages.
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.
N/A
SRPMS
- perl-DBI-1.641-8.module+el8+2028+f328b067.src.rpm
MD5: e086c89e1b16c4407a9a7fa9b8045d84
SHA-256: de806d01c8c713201f2af31724632868aaa351c6a1962d922d9047e79ebfc429
Size: 619.13 kB
Asianux Server 8 for x86_64
- perl-DBI-1.641-8.module+el8+2028+f328b067.x86_64.rpm
MD5: 287df4e3f1cc6d54e5bebdbe4ae8271f
SHA-256: bd643b252cea1c0e254eb1bde9c5b2bfee75058f862b857e3c5bcf30b58e9d8f
Size: 738.90 kB - perl-DBI-debugsource-1.641-8.module+el8+2028+f328b067.x86_64.rpm
MD5: 0e352c9fa6117e7688185f0ce8b9c360
SHA-256: f0e44629ae2c06b46bcdafe0b8a6e934d75236e2d6fb072d2880cbf2fb6b7f05
Size: 122.40 kB