Bug#1142072: libdbi-perl: CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082
Salvatore Bonaccorso
carnil at debian.org
Tue Jul 14 21:38:50 BST 2026
Source: libdbi-perl
Version: 1.650-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerabilities were published for libdbi-perl.
CVE-2026-15043[0]:
| DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have
| inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's
| built-in mini-SQL engine, evaluated WHERE predicates incorrectly in
| some cases. In the non-numeric string branch of the is_matched
| method, <= was evaluated using Perl's ge operator, and >= was
| evaluated using Perl's le operator. SQL::Nano is the fallback query
| engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style
| drivers) whenever SQL::Statement is not installed, and is forced
| whenever DBI_SQL_NANO=1. Queries over such tables use these
| predicates directly. The impact depends on the context. Where an
| application relies on a WHERE clause to filter file-backed data for
| policy or authorization, an inverted <=/>= comparison silently
| returns the wrong rows.
CVE-2026-15392[1]:
| DBD::File versions before 1.651 for Perl do not ensure the table
| file is not a symlink to an untrusted location. The
| complete_table_name method builds the absolute table file path
| without checking whether the file is a symbolic link. A link inside
| the data directory can point to a table file at any path outside of
| the configured f_dir and f_dir_search directories. Callers of file-
| based drivers can read or write files outside of the data directory.
CVE-2026-60081[2]:
| DBI::ProfileData versions before 1.651 for Perl do not limit the
| path index. The path index column of profile dump files is used to
| allocate an array of data for the parser. An unbounded value allows
| an attacker to specify a large index and consume available memory.
CVE-2026-60082[3]:
| DBI versions before 1.651 for Perl do not enforce statement handle
| consistency with the row. When the statement handle had no fields
| but the source row was non-empty, the internal row-buffer helper
| would read from a negative array index. This could be triggered by
| a caller supplying inconsistent metadata and rows to the prepare
| method.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-15043
https://www.cve.org/CVERecord?id=CVE-2026-15043
[1] https://security-tracker.debian.org/tracker/CVE-2026-15392
https://www.cve.org/CVERecord?id=CVE-2026-15392
[2] https://security-tracker.debian.org/tracker/CVE-2026-60081
https://www.cve.org/CVERecord?id=CVE-2026-60081
[3] https://security-tracker.debian.org/tracker/CVE-2026-60082
https://www.cve.org/CVERecord?id=CVE-2026-60082
Regards,
Salvatore
More information about the pkg-perl-maintainers
mailing list