CVE-2026-73194

Oracle Communications: Improper Validation of Specified Quantity in Input

criticalEPSS 0.5%

Affected

  • debian/libdbi-perl 1.652-2~deb13u1..*

Description

DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing ':2147483648' leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following '?' then expands through `sprintf(start, ":p%d", idx++)` to ':p-2147483648', 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes. Any caller that preparses an untrusted statement into ':pN' style placeholders gets a heap out-of-bounds write that grows with the number of '?' marks following the poisoned placeholder. The '?' and '%s' return styles compare the parsed number against the expected sequence and error out, and are unaffected.

Affected operating systems

  • linux

    ubuntu / libdbi-perlbionic

  • linux

    ubuntu / libdbi-perlfocal

  • linux

    ubuntu / libdbi-perljammy

  • linux

    ubuntu / libdbi-perlnoble

  • linux

    ubuntu / libdbi-perlresolute

  • linux

    ubuntu / libdbi-perltrusty

  • linux

    ubuntu / libdbi-perlxenial

Metrics

9.1
Source: cna-v3
40.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-15 12:09 UTC
CWE-1284, CWE-787

Weakness classes (CWE)

  • CWE-1284Base

    Improper Validation of Specified Quantity in Input

    The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

    cwe.mitre.org →
  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-17 21:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
    • SSVC: {"id":"CVE-2026-73194","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  2. New CVE Received2026-08-15 13:17 UTC· 9b29abf9-4ab0-4765-b253-1875cd9b441e
    • Affected: …
    • Description: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing ':2147483648' leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following '?' then expands through `sprintf(start, ":p%d", idx++)` to ':p-2147483648', 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes. Any caller that preparses an untrusted statement into ':pN' style placeholders gets a heap out-of-bounds write that grows with the number of '?' marks following the poisoned placeholder. The '?' and '%s' return styles compare the parsed number against the expected sequence and error out, and are unaffected.
    • CWE: CWE-787
    • CWE: CWE-1284

Linked advisories