CVE-2026-88816: fallo de gravedad alta en DBI
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 0.6%
probabilidad de explotación
0.6%top 52% de las CVE
explotación observada
noninguna fuente lo reporta
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName.
fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault.
This can be triggered with the following code:
my $dbh = DBI->connect( "dbi:ExampleP:", "", "",
{ RaiseError => 0, PrintError => 0 } );
$dbh->{FetchHashKeyName} = 42;
my $sth = $dbh->prepare("select mode, size, name from .");
$sth->execute;
$sth->fetchrow_hashref;
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
DBICVEs relacionadas — DBI
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-73193CRITICALDBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparseEPSS 0.6%CVE-2026-14380HIGHDBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced ProfileEPSS 0.5%CVE-2026-73194CRITICALDBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparseEPSS 0.5%CVE-2026-78030CRITICALDBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBMEPSS 0.4%CVE-2026-88815MEDIUMDBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpvEPSS 0.2%