CVE-2026-9698 PUBLISHED

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer

Assigner: CPANSec
Reserved: 27.05.2026 Published: 09.06.2026 Updated: 09.06.2026

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.

Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.

Attackers that can influence the error text in an application can trigger a buffer overflow.

Product Status

Vendor HMBRAND
Product DBI
Versions Default: unaffected
  • affected from 0 to 1.648 (excl.)

Solutions

Upgrade to DBI 1.648 or later.

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE