PT-2026-99933 · Cpan · Dbi

·

CVE-2026-88816

·

Published

2026-09-28

·

Updated

2026-10-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions DBI versions prior to 1.654
Description Perl DBI incorrectly treats numeric values as strings within the FetchHashKeyName attribute. The fetchrow hashref() function uses the string pointer of FetchHashKeyName as the key name without performing stringification first. If FetchHashKeyName is assigned an integer (IV) or floating-point (NV) value, the resulting pointer is invalid, leading to a segmentation fault when the key name is read.
Recommendations Update to version 1.654 or later.

Exploit

Fix

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88816
ECHO-5F1F-BFBE-E4BD
GHSA-F4QX-MR9M-Q2HQ
OPENSUSE-SU-2026:11966-1

Affected Products

Dbi