Debian alert DLA-4764-1 (libdbi-perl)
| From: | Guilhem Moulin <guilhem@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4764-1] libdbi-perl security update | |
| Date: | Mon, 31 Aug 2026 14:51:14 +0200 | |
| Message-ID: | <apV4wBJ_IjKbeCzY@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4764-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin August 31, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libdbi-perl Version : 1.643-3+deb11u2 1.643-4+deb12u2 CVE ID : CVE-2026-14380 CVE-2026-14739 CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082 CVE-2026-73193 CVE-2026-73194 Debian Bug : 1141667 1142072 1144470 1144471 Multiple vulnerabilities were discovered in libdbi-perl, the Perl Database Interface (DBI), which may lead to arbitrary code execution, denial of service, file-backed filter bypass or path traversal. CVE-2026-14380 It was found that missing input validation when interpolating the package name in a string `eval` may lead to arbitrary Perl code execution from an attacker able controlling the Profile attribute, for instance via the `DBI_PROFILE` environment variable or a DSN driver-attribute clause `dbi:Driver(Profile=>SPEC):db`. CVE-2026-14739 It was found that preparsing SQL statements with an excessively high (over one million) number of placeholders could lead to heap overflow. This update sets a hard limit of 99999 placeholders. CVE-2026-14740 It was found that preparsing an SQL statement starting with a comment line could lead to an out-of-bounds read by one byte. CVE-2026-15043 It was found that DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated `WHERE` predicates by incorrectly inverting `<=` and `>=` SQL operators on text, which may lead to file-backed filter bypass. CVE-2026-15392 It was found that DBD::File did not check whether the table file is a symbolic link, which may lead to path traversal if the target points outside the `f_dir` and `f_dir_search` directories. This issue stems from an incomplete fix for CVE-2014-10401 and CVE-2014-10402. CVE-2026-60081 It was found that DBI::ProfileData did not limit the path index when parsing a profile-dump file, which may lead to denial of service. This updates adds a configurable maximum path depth `$DBI::Profile::MAX_PATH_DEPTH`, with a default value of 256. CVE-2026-60082 It was found that missing statement handle consistency checks could lead to an out-of-bounds read when a statement handle had no fields and the source row was non-empty. CVE-2026-73193 A heap out-of-bounds write issue was found on 32-bit platforms due to integer overflow in the output buffer size computed by the `preparse()` function. This updates limits the size of SQL statements to 292 MiB. CVE-2026-73194 A heap out-of-bounds write issue was found due to unvalidated numeric placeholder in the `preparse()` function. This issue stems from an incomplete fix for CVE-2026-14739. For Debian 11 bullseye, these problems have been fixed in version 1.643-3+deb11u2. For Debian 12 bookworm, these problems have been fixed in version 1.643-4+deb12u2. We recommend that you upgrade your libdbi-perl packages. For the detailed security status of libdbi-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libdbi-perl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmqVeMAACgkQ05pJnDwh pVLVKQ/8CVJoChaUL3Dw6suWv840YOX5EOTfzjPejxsmWtCo/rXzVbpRgk1HfvTH Is5W9N/hz8K6dL8S3xcQb+IPNBqIVIS7ukVGunWR8mhRZDvIdUBULgQQgVPsN0PB oIebMQtyN/OL0bOuR5uK1gm3cvkvn5uKSh7yVyCWNMOSTMcuyfQ8K8mJ90RnciRr 7E1Y5FnEPMTfooJLh2UJAlZeo5JTknjvRYbELHN9neVOA8cNblrx25ZE7Xpj4p3r ucn8OJb57ZRENPTF4bwoD/TfTXP6duSjAae5b1bDwaJju+2KxvLm4Jae2yOUS61o tuUkERR9vEE0rLVPSa6Y+G10zlJmqiWiCNEHSKwPfLPnUTWnkgXToJmNiLNWTVdt shNyt7cvczR6L5bQBeFtZfTnPgCJBP34BfLkSkeodaaorWPHPIjjQeKN4kCPgAc5 T2gDrKQilAw9bdxhvY/HmtKT0STNf2bG1XURUVTk78x+ST8o4t8RSW06d9Q1emFi pgyyihbsAWAZ6mzzb4XTXJ/M4oplmhymDofcLFz97U3XuYp3hYxhIsTjqvkHbI7/ iRwuitzWFg4mlcmNHq2s3vHC83pKVNSBEqLhLC5mywhMkZyx2iMeAzbe+vzG6ID3 bXhiwq+nwZZOrZR7JT5BxASw2ugD3ehiXTm0dvkiCfDaNXdzby8= =3/o4 -----END PGP SIGNATURE-----
