6.2

CVE-2026-88815

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.

When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.

This is reachable in Perl using the sql_type_cast function:

  my $num = 42;
  DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Collection URLhttps://cpan.org/modules
≫
Paket DBI
Default Statusunaffected
Version 0
Version < 1.654
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.2 2.5 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://github.com/perl5-dbi/dbi/security/advisories/GHSA-c8vq-w3wr-6979
https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d6702.patch
https://metacpan.org/release/HMBRAND/DBI-1.654/changes
http://www.openwall.com/lists/oss-security/2026/09/28/12