Bug 2542559 (CVE-2026-88815) - CVE-2026-88815 perl-DBI: perl-DBI: Denial of Service via invalid memory read during numeric type casting
Summary: CVE-2026-88815 perl-DBI: perl-DBI: Denial of Service via invalid memory read ...
Keywords:
Status: NEW
Alias: CVE-2026-88815
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-28 16:31 UTC by OSIDB Bzimport
Modified: 2026-09-28 16:39 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-28 16:31:29 UTC
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.

When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.

This is reachable in Perl using the sql_type_cast function:

  my $num = 42;
  DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );


Note You need to log in before you can comment on or make changes to this bug.