7.5

CVE-2026-88816

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName.

fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault.

This can be triggered with the following code:

   my $dbh = DBI->connect( "dbi:ExampleP:", "", "",
       { RaiseError => 0, PrintError => 0 } );
   $dbh->{FetchHashKeyName} = 42;

   my $sth = $dbh->prepare("select mode, size, name from .");
   $sth->execute;
   $sth->fetchrow_hashref;
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Collection URLhttps://cpan.org/modules
≫
Paket DBI
Default Statusunaffected
Version 0
Version < 1.654
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://metacpan.org/release/HMBRAND/DBI-1.654/changes
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-f4qx-mr9m-q2hq
https://github.com/perl5-dbi/dbi/commit/70962570212dc60a5428098cf2a0462ad5945851.patch
http://www.openwall.com/lists/oss-security/2026/09/28/13