CVE-2026-88816 Details
Description
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault. This can be triggered with the following code: my $dbh = DBI->connect( "dbi:ExampleP:", "", "", { RaiseError => 0, PrintError => 0 } ); $dbh->{FetchHashKeyName} = 42; my $sth = $dbh->prepare("select mode, size, name from ."); $sth->execute; $sth->fetchrow_hashref;
A segmentation fault vulnerability has been identified in the DBI module for Perl, affecting versions prior to 1.654. The issue arises because the module improperly handles numeric values in the FetchHashKeyName attribute, treating them as strings without proper conversion. This flaw can lead to a crash when the fetchrow_hashref method is called, as the invalid pointer from the FetchHashKeyName is accessed, causing a segmentation fault. The vulnerability can be reproduced by setting FetchHashKeyName to a numeric value and then executing a SQL query that retrieves column data.
Users are advised to upgrade to DBI version 1.654 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/perl5-dbi/dbi/security/advisories/GHSA-f4qx-mr9m-q2hq | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/perl5-dbi/dbi/commit/70962570212dc60a5428098cf2a0462ad5945851.patch | CPANSec | Source CodeVendor |
| https://github.com/perl5-dbi/dbi/security/advisories/GHSA-f4qx-mr9m-q2hq | CPANSec | AdvisoryExploitRemedyVendor |
| https://metacpan.org/release/HMBRAND/DBI-1.654/changes | CPANSec | Release NotesVendor |
| http://www.openwall.com/lists/oss-security/2026/09/28/13 | CVE | AdvisoryExploitMailing ListRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | CPANSec |
Affected Products
| Product | Versions |
|---|---|
| DBI | <= 1.653 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | CVE Modified | CVE |
| Sep 28, 2026 | New CVE Received | CPANSec |
Volerion