Bug#1144470: libdbi-perl: CVE-2026-73193
Salvatore Bonaccorso
carnil at debian.org
Sat Aug 15 15:37:21 BST 2026
Source: libdbi-perl
Version: 1.651-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerability was published for libdbi-perl.
CVE-2026-73193[0]:
| DBI versions before 1.652 for Perl allow a heap out-of-bounds write
| on 32-bit perl via an integer wraparound in the output buffer size
| computed by preparse. preparse reserves its output buffer with
| `newSV(strlen(statement) * 7 + 16)`, budgeting seven output bytes
| per input byte for the longest ':p99999' expansion. The product is
| computed in STRLEN, which is 32 bits wide on a 32-bit perl build, so
| a statement of 613,566,757 bytes multiplies to 4,294,967,299, wraps
| modulo 2^32 to 3, and reserves 19 bytes. The parser then copies the
| statement out through a raw pointer with no capacity check, writing
| the whole 585 MB input past the end of the allocation. The 99,999
| placeholder limit does not bound this path, which is reached by
| ordinary non-placeholder content. Any caller that passes an
| untrusted statement of that length to preparse on a 32-bit perl gets
| a heap out-of-bounds write of attacker controlled bytes. Builds with
| a 64-bit STRLEN are not affected, since the wrap there needs a
| statement of about 2.3 exabytes.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-73193
https://www.cve.org/CVERecord?id=CVE-2026-73193
[1] https://lists.security.metacpan.org/cve-announce/msg/42707360/
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the pkg-perl-maintainers
mailing list