Bug 2521667 (CVE-2026-78183)

Summary: CVE-2026-78183 perl-DBD-Pg: DBD::Pg: Heap out-of-bounds write can lead to memory corruption.
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in DBD::Pg for Perl. This vulnerability involves a heap out-of-bounds write in the `quote_float` function when processing special numeric literals such as "Infinity". An attacker could potentially exploit this by providing specific input to the `$dbh->quote` method, leading to a two-byte memory overflow. This memory corruption could result in a denial of service or potentially lead to arbitrary code execution.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-23 20:01:26 UTC
DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float.

quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL.  But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL.

This can be reached by the $dbh->quote method, for example

    $dbh->quote( "Infinity", DBI::SQL_NUMERIC ).

This regression was introduced in 3.21.0 by the quote.c rewrite.