DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
Published Jul 7, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.39%
Description
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment.
The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.
Affected products
-
Affected
- ≥ 0, < 1.650
No data.
Red Hat Enterprise Linux 10
perl-DBI
Fix deferred
Red Hat Enterprise Linux 6
perl-DBI
Out of support scope
Red Hat Enterprise Linux 7
perl-DBI
Out of support scope
Red Hat Enterprise Linux 8
perl-DBI
Fix deferred
Red Hat Enterprise Linux 8
perl-DBI:1.641/perl-DBI
Fix deferred
Red Hat Enterprise Linux 9
perl-DBI
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | perl-DBI | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | perl-DBI | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | perl-DBI | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | perl-DBI | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | perl-DBI:1.641/perl-DBI | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | perl-DBI | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to DBI version 1.650 or later.
References (9)
- http://www.openwall.com/lists/oss-security/2026/07/07/17 Mailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-14740 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2497905 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42125 Advisory
- https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01.patch patch
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg vendor-advisoryVendor Advisory
- https://metacpan.org/release/HMBRAND/DBI-1.650/changes release-notesRelease Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-14740
- https://www.cve.org/CVERecord?id=CVE-2026-14740
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/07/17 | Mailing ListPatchThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-14740 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2497905 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42125 | Advisory | |
| https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01.patch | patch | |
| https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg | vendor-advisoryVendor Advisory | |
| https://metacpan.org/release/HMBRAND/DBI-1.650/changes | release-notesRelease Notes | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-14740 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-14740 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data