CVE-2026-14740
debian libdbi-perl: Lesezugriff ausserhalb der Grenzen
criticalEPSS 0.4%
Affected
- debian/libdbi-perl
1.652-2~deb13u1..*
Description
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.
Affected operating systems
linux
debian / libdbi-perltrixie
Metrics
Show all metrics
Severity
critical
74.67
no public PoC known
9.1
Published
2026-07-07 22:05 UTC
CWE-125
Weakness classes (CWE)
CWE-125Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
cwe.mitre.org →
References & sources
- https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01.patchpatch
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xgvendor-advisory
- https://metacpan.org/release/HMBRAND/DBI-1.650/changesrelease-notes
- http://www.openwall.com/lists/oss-security/2026/07/07/17
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-07-07 23:16 UTC· 9b29abf9-4ab0-4765-b253-1875cd9b441e
- Affected: DBI
- Description: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.
- CWE: CWE-125
- Reference: https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01.patch