PT-2026-46958 · Dbi+3 · Dbi+3

CVE-2026-10879

·

Published

2026-06-05

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DBI versions prior to 1.648
Description A heap overflow occurs when preparsing SQL statements containing more than 9 binders. The preparse() function expands SQL placeholder characters into numbered binders using the format :pN, but the buffer allocation is limited to three characters per binder. This leads to an overflow when placeholders reach 10 or more, as they require four or more characters (e.g., placeholders 10-99 require four characters, and 100-999 require five).
Recommendations Update to version 1.648.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38512
ALSA-2026:38513
ALSA-2026:62667
AZL-89559
CVE-2026-10879
ECHO-289F-C6B8-0D5E
ECHO-A14B-4653-C837
OESA-2026-2684
OPENSUSE-SU-2026:10986-1
OPENSUSE-SU-2026:21029-1
RHSA-2026:38512
RHSA-2026:38513
RHSA-2026:38901
RHSA-2026:49514
RHSA-2026:49612
RHSA-2026:52772
SUSE-SU-2026:22257-1
SUSE-SU-2026:22330-1
SUSE-SU-2026:2749-1
USN-8466-1

Affected Products

Dbi
Linuxmint
Rocky Linux
Ubuntu