Bug 2542560 (CVE-2026-88816) - CVE-2026-88816 perl-DBI: perl-DBI: Denial of Service via numeric FetchHashKeyName attribute
Summary: CVE-2026-88816 perl-DBI: perl-DBI: Denial of Service via numeric FetchHashKey...
Keywords:
Status: NEW
Alias: CVE-2026-88816
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2542966
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-28 16:31 UTC by OSIDB Bzimport
Modified: 2026-09-29 06:44 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-28 16:31:44 UTC
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName.

fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault.

This can be triggered with the following code:

   my $dbh = DBI->connect( "dbi:ExampleP:", "", "",
       { RaiseError => 0, PrintError => 0 } );
   $dbh->{FetchHashKeyName} = 42;

   my $sth = $dbh->prepare("select mode, size, name from .");
   $sth->execute;
   $sth->fetchrow_hashref;


Note You need to log in before you can comment on or make changes to this bug.