MGASA-2026-0390
Dashboard / Vulnerabilities / MGASA-2026-0390
MGASA-2026-0390
Summary: Updated perl-DBI packages fix security vulnerabilities
Details: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.
References: https://advisories.mageia.org/MGASA-2026-0390.html, https://bugs.mageia.org/show_bug.cgi?id=36144, https://www.openwall.com/lists/oss-security/2026/08/15/2, https://github.com/perl5-dbi/dbi/security/advisories/GHSA-wj3v-c3hh-mhqr, https://www.openwall.com/lists/oss-security/2026/08/15/3, https://github.com/perl5-dbi/dbi/security/advisories/GHSA-623j-hfpc-mrc4
Affected packages
Package
Name: perl-DBI
Purl: pkg:rpm/mageia/perl-DBI?arch=source&distro=mageia-10
Affected ranges
Type: ECOSYSTEM
Events:
